CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0252 [1.00] [H/H] Vulnerabilities fixed in Oracle Fusion middleware

unknownCVE-2026-47056CVE-2026-60217CVE-2026-60358CVE-2026-60360CVE-2026-60365CVE-2026-60366
Oracle has fixed a large number of vulnerabilities in various Oracle middleware products, including Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler), and Oracle WebCenter Content. The total number of vulnerabilities fixed in these updates is 345. The most severe vulnerabilities, 9 in total, have the highest score of 10.0 and are found in various Oracle middleware components, allowing unauthenticated external attackers to achieve complete system compromise. Attackers can execute arbitrary code or gain full control over the system without authentication via HTTP, LDAP, SOAP, or other network interfaces. Some vulnerabilities can lead to unauthorized access, modification, or deletion of critical data. The impact may also extend to other Oracle products that depend on the affected middleware components. In addition to these 9 vulnerabilities with the highest score, another 145 vulnerabilities have been fixed with a CVSS score of 9 to 9.9. Many of these vulnerabilities can also be exploited remotely without prior authentication and can lead to arbitrary code execution, access to sensitive data, or complete system compromise. The remaining vulnerabilities have scores lower than 9. It is too extensive to include all detailed information in this advisory, and the NCSC therefore refers to the attached reference. Due to the large number and severity of these vulnerabilities, the NCSC considers it highly likely that widespread exploitation will occur in the short term. The NCSC therefore advises to carefully review the attached reference and urgently deploy the provided updates.

CSIRTS triage

What
A large number of vulnerabilities have been fixed, including those allowing complete system compromise.
Who is affected
Users of various Oracle middleware products.
Urgency
Remediation is critical due to the high severity of the vulnerabilities, with some scoring 10.0.
Action
Apply the latest updates provided by Oracle.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Oracle Fusion Middleware

Get an email when a new Oracle Fusion Middleware advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0252

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-47056coverage & exploitation statusNVD · CVE.org
CVE-2026-60217coverage & exploitation statusNVD · CVE.org
CVE-2026-60358coverage & exploitation statusNVD · CVE.org
CVE-2026-60360coverage & exploitation statusNVD · CVE.org
CVE-2026-60365coverage & exploitation statusNVD · CVE.org
CVE-2026-60366coverage & exploitation statusNVD · CVE.org
CVE-2026-60379coverage & exploitation statusNVD · CVE.org
CVE-2026-60389coverage & exploitation statusNVD · CVE.org
CVE-2026-60644coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Oracle Fusion middleware

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories