NCSC-2026-0254 [1.00] [M/H] Vulnerabilities fixed in Oracle database products
Oracle has fixed 158 vulnerabilities in Oracle Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, and TimesTen In-Memory Database. Of these vulnerabilities, 91 are from third-party products for which updates have previously been released and are now processed by Oracle, or concern vulnerabilities that cannot lead to exploitation because they are in parts of the products that are not accessible. The six most severe vulnerabilities have received a CVSS score of 9 or higher. The vulnerability in Eclipse Jetty's HTTP/1.1 parser, used in Oracle REST Data Services versions 24.2.0 to 26.1.0, concerns incorrect parsing of chunked transfer encoding extensions with unclosed quoted strings, allowing HTTP request smuggling. This can lead to cache poisoning, bypass of access control, session hijacking, and unauthorized access to endpoints. Perl versions from 5.9.4 to 5.43.9 contain a vulnerable Compress::Raw::Zlib module due to an outdated zlib library with multiple security issues, including CVE-2026-3381 and CVE-2026-27171. This vulnerability is relevant for Perl distributions often deployed in Red Hat Enterprise Linux and OpenShift Container Platform environments. Apache Kafka versions 4.1.0 and 4.1.1 contain a vulnerability in JWT token validation where the default validator accepts any JWT token without proper validation, potentially allowing unauthorized access. This is resolved by explicitly setting the validator or upgrading to version 4.1.2 or higher. Oracle Communications Unified Assurance Message Bus components versions 6.1.1 to 7.0.0, which use Apache Kafka, contain a vulnerability that allows unauthenticated network attackers to gain unauthorized access and modify critical data. Oracle Net Services versions 19.3 to 19.31, 21.3.
CSIRTS triage
- What
- Multiple vulnerabilities have been fixed, including one that allows HTTP request smuggling.
- Who is affected
- Users of various Oracle Database products, including Oracle REST Data Services versions 24.2.0 to 26.1.0.
- Urgency
- Remediation is necessary due to the potential for exploitation of the vulnerabilities.
- Action
- Apply the latest updates from Oracle.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle Database
Get an email when a new Oracle Database advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0254
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-33810.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-271710.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-3381 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27171 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- unknownNCSC-2026-0256 [1.00] [M/H] Vulnerabilities fixed in Oracle Communicationsncsc-nl
- unknownNCSC-2026-0255 [1.00] [M/H] Vulnerabilities fixed in Oracle Commerce Platformncsc-nl
- low[UPDATE] [low] zlib: Vulnerability allows Denial of Servicecert-bund
Recent advisories for Oracle database products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-60411: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database…nvd · 2026-07-21
- mediumCVE-2026-60410: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database…nvd · 2026-07-21
- mediumCVE-2026-60409: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database…nvd · 2026-07-21
- mediumCVE-2026-60408: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database…nvd · 2026-07-21
- mediumCVE-2026-60407: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database…nvd · 2026-07-21
- mediumCVE-2026-60406: Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database…nvd · 2026-07-21
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30