NCSC-2026-0256 [1.00] [M/H] Vulnerabilities fixed in Oracle Communications
Oracle has fixed vulnerabilities in Communications products and underlying third-party software. There are a total of 213 vulnerabilities, of which 67 are in Oracle products and 146 in third-party products for which updates have previously been released and are now included in these Oracle updates. The most severe vulnerabilities, 12 in total, have received a CVSS score of 9 or higher and are described below. 11 of these are in embedded third-party products. The remaining vulnerabilities have lower scores, and it is too extensive to include detailed information in this advisory. For this, the NCSC refers to the attached reference. Oracle Communications Converged Application Server versions 8.2 and 8.3 contain a vulnerability that allows unauthorized network access and can lead to full system takeover. Libtiff up to version 4.7.0 contains a write-what-where vulnerability and a stack-based buffer overflow that can be triggered by specially crafted TIFF files, potentially leading to code execution or crashes. Apache Tomcat versions 8.5.0 to 11.0.5 contain vulnerabilities that allow specially crafted HTTP requests to bypass rewrite rules and security constraints, potentially resulting in data disclosure, modification, or denial of service. Eclipse Jetty's HTTP/1.1 parser improperly processes chunked transfer encoding extensions with improperly closed quotes, allowing request smuggling and potentially leading to cache poisoning, access control bypass, and session hijacking. Perl versions with an outdated vendored zlib in Compress::Raw::Zlib contain multiple security issues that have been resolved in a specific commit. Lodash versions up to 4.17.23 contain multiple vulnerabilities including code injection via untrusted keys in _.template, prototype pollution, regex denial of service, and command injection. Apache HTTP Server versions 2.4.0 to 2.4.67 contain various vulnerabilities in multiple modules.
CSIRTS triage
- What
- A vulnerability allows unauthorized network access, potentially leading to full system takeover.
- Who is affected
- Deployments of Oracle Communications Converged Application Server versions 8.2 and 8.3.
- Urgency
- Remediation is urgent due to the high severity of the vulnerabilities, with some scoring 9 or higher.
- Action
- Apply the latest updates provided by Oracle.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle Communications
Get an email when a new Oracle Communications advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0256
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-99000.74% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all scored CVEs.
- Moderate exploitation riskCVE-2025-316514.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all scored CVEs.
- Moderate exploitation riskCVE-2026-23321.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
- Low exploitation riskCVE-2026-41760.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
- Low exploitation riskCVE-2026-33810.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-271710.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Moderate exploitation riskCVE-2026-48002.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 84% of all scored CVEs.
- Elevated exploitation riskCVE-2021-2333721.3% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all scored CVEs.
- Low exploitation riskCVE-2026-291670.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
- Low exploitation riskCVE-2026-335570.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-9900 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-31651 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-2332 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4176 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3381 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27171 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4800 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-23337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-29167 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33557 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34520 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-39892 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40976 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42779 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61223 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Red Hat Enterprise Linux and Satellite (satellite/iop-remediations-rhel9 container image): Mul…cert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownUSN-8589-1: Apache HTTP Server vulnerabilitiesubuntu
- unknownNCSC-2026-0259 [1.00] [M/H] Vulnerabilities fixed in Oracle Analyticsncsc-nl
- unknownNCSC-2026-0258 [1.00] [M/H] Vulnerabilities fixed in Oracle Financial Servicesncsc-nl
- unknownNCSC-2026-0255 [1.00] [M/H] Vulnerabilities fixed in Oracle Commerce Platformncsc-nl
Recent advisories for Oracle Communications
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund · 2026-07-28
- highCVE-2026-61226: Vulnerability in the Oracle Communications Converged Application Server product of Oracle Comm…nvd · 2026-07-21
- highCVE-2026-61225: Vulnerability in the Oracle Communications Converged Application Server product of Oracle Comm…nvd · 2026-07-21
- highCVE-2026-61224: Vulnerability in the Oracle Communications Converged Application Server product of Oracle Comm…nvd · 2026-07-21
- criticalCVE-2026-61223: Vulnerability in the Oracle Communications Converged Application Server product of Oracle Comm…nvd · 2026-07-21
- mediumCVE-2026-61143: Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Co…nvd · 2026-07-21
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30