NCSC-2026-0252 [1.00] [H/H] Vulnerabilities fixed in Oracle Fusion middleware
Oracle has fixed a large number of vulnerabilities in various Oracle middleware products, including Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler), and Oracle WebCenter Content. The total number of vulnerabilities fixed in these updates is 345. The most severe vulnerabilities, 9 in total, have the highest score of 10.0 and are found in various Oracle middleware components, allowing unauthenticated external attackers to achieve complete system compromise. Attackers can execute arbitrary code or gain full control over the system without authentication via HTTP, LDAP, SOAP, or other network interfaces. Some vulnerabilities can lead to unauthorized access, modification, or deletion of critical data. The impact may also extend to other Oracle products that depend on the affected middleware components. In addition to these 9 vulnerabilities with the highest score, another 145 vulnerabilities have been fixed with a CVSS score of 9 to 9.9. Many of these vulnerabilities can also be exploited remotely without prior authentication and can lead to arbitrary code execution, access to sensitive data, or complete system compromise. The remaining vulnerabilities have scores lower than 9. It is too extensive to include all detailed information in this advisory, and the NCSC therefore refers to the attached reference. Due to the large number and severity of these vulnerabilities, the NCSC considers it highly likely that widespread exploitation will occur in the short term. The NCSC therefore advises to carefully review the attached reference and urgently deploy the provided updates.
CSIRTS triage
- What
- A large number of vulnerabilities have been fixed, including those allowing complete system compromise.
- Who is affected
- Users of various Oracle middleware products.
- Urgency
- Remediation is critical due to the high severity of the vulnerabilities, with some scoring 10.0.
- Action
- Apply the latest updates provided by Oracle.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle Fusion Middleware
Get an email when a new Oracle Fusion Middleware advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0252
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-470560.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-602170.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-603580.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-603600.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-603650.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-603660.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-603790.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-603890.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-606440.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-47056 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60217 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60358 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60360 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60365 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60366 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60379 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60389 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60644 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
- criticalCVE-2026-60366: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (co…nvd
- criticalCVE-2026-60644: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: …nvd
- criticalCVE-2026-60389: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component:…nvd
- criticalCVE-2026-60379: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component:…nvd
- criticalCVE-2026-60365: Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware …nvd
- criticalCVE-2026-60360: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: …nvd
- criticalCVE-2026-60358: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Aut…nvd
- criticalCVE-2026-60217: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). S…nvd
- criticalCVE-2026-47056: Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Re…nvd
Recent advisories for Oracle Fusion middleware
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund · 2026-07-23
- highCVE-2026-61246: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (co…nvd · 2026-07-22
- highCVE-2026-60455: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (co…nvd · 2026-07-22
- highCVE-2026-60439: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (co…nvd · 2026-07-22
- highCVE-2026-60373: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (co…nvd · 2026-07-22
- criticalCVE-2026-60372: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (co…nvd · 2026-07-22
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30