NCSC-2026-0200 [1.00] [M/H] Vulnerabilities fixed in Oracle Communications
Oracle has fixed vulnerabilities in Oracle Communications. The vulnerabilities are in two underlying products: SQLite and Log4j and have been previously fixed by the developers of these products. Oracle has incorporated the updates into its own software. In SQLite, a remote attacker can leak heap memory via specially crafted ZIP files due to an information leak in the zipfileInflate function of the zipfile extension. In Log4j, incorrect serialization of non-finite floating-point values such as NaN or infinity in the JsonTemplateLayout leads to invalid JSON output, which can disrupt downstream log processing systems when applications log MapMessages controlled by the attacker, causing a denial of service in log analysis workflows.
CSIRTS triage
- What
- Vulnerabilities in SQLite and Log4j can lead to information leaks and denial of service.
- Who is affected
- Deployments of Oracle Communications that utilize SQLite and Log4j.
- Urgency
- Remediation is important to prevent information leaks and disruptions in log processing.
- Action
- Incorporate the latest updates for SQLite and Log4j.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle Communications
Get an email when a new Oracle Communications advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0200
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-708730.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344810.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-70873 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34481 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Servicesncsc-nl
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Managerncsc-nl
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Financial Services Applications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Hyperion: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Retail Applications: Vulnerability compromises integritycert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21