NCSC-2026-0202 [1.00] [M/H] Vulnerabilities fixed in Oracle Enterprise Manager
Oracle has fixed multiple vulnerabilities in Oracle Enterprise Manager versions 13.5 and 24.1. The vulnerabilities in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allow an attacker with low or no privileges and network access via HTTP or HTTPS to gain full control over the platform. Some vulnerabilities do not require authentication and can lead to unauthorized data modification, denial-of-service, or complete system compromise. Additionally, an attacker with SSH access can also achieve full system compromise. The vulnerabilities may also impact other Oracle products that are integrated with the platform. Furthermore, there is a vulnerability in Apache Log4j's JsonTemplateLayout up to version 2.25.3 that generates incorrect JSON output when serializing non-finite floating-point values, which can disrupt downstream log processing systems when MapMessages are logged.
CSIRTS triage
- What
- Vulnerabilities allow an attacker to gain full control over the platform, potentially without authentication.
- Who is affected
- Deployments of Oracle Enterprise Manager versions 13.5 and 24.1.
- Urgency
- Remediation is critical due to the risk of complete system compromise.
- Action
- Update to the latest versions of Oracle Enterprise Manager.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle Enterprise Manager
Get an email when a new Oracle Enterprise Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0202
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-344810.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468320.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468520.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468530.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468540.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468550.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468560.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468570.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468580.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-468640.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34481 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46832 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46852 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46853 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46854 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46855 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46856 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46857 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46858 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46864 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46865 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46866 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46867 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46868 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46872 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46875 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Servicesncsc-nl
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Managerncsc-nl
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Financial Services Applications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Hyperion: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Retail Applications: Vulnerability compromises integritycert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
Recent advisories for Oracle Enterprise Manager
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Managerncsc-nl · 2026-08-19
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund · 2026-08-19
- highCVE-2026-70922: Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Fi…nvd · 2026-08-18
- highCVE-2026-70737: Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle En…nvd · 2026-08-18
- highCVE-2026-70684: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Mana…nvd · 2026-08-18
- highCVE-2026-61300: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Mana…nvd · 2026-08-18
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21