CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0256 [1.00] [M/H] Vulnerabilities fixed in Oracle Communications

unknownCVE-2025-9900CVE-2025-31651CVE-2026-2332CVE-2026-4176CVE-2026-3381CVE-2026-27171
Oracle has fixed vulnerabilities in Communications products and underlying third-party software. There are a total of 213 vulnerabilities, of which 67 are in Oracle products and 146 in third-party products for which updates have previously been released and are now included in these Oracle updates. The most severe vulnerabilities, 12 in total, have received a CVSS score of 9 or higher and are described below. 11 of these are in embedded third-party products. The remaining vulnerabilities have lower scores, and it is too extensive to include detailed information in this advisory. For this, the NCSC refers to the attached reference. Oracle Communications Converged Application Server versions 8.2 and 8.3 contain a vulnerability that allows unauthorized network access and can lead to full system takeover. Libtiff up to version 4.7.0 contains a write-what-where vulnerability and a stack-based buffer overflow that can be triggered by specially crafted TIFF files, potentially leading to code execution or crashes. Apache Tomcat versions 8.5.0 to 11.0.5 contain vulnerabilities that allow specially crafted HTTP requests to bypass rewrite rules and security constraints, potentially resulting in data disclosure, modification, or denial of service. Eclipse Jetty's HTTP/1.1 parser improperly processes chunked transfer encoding extensions with improperly closed quotes, allowing request smuggling and potentially leading to cache poisoning, access control bypass, and session hijacking. Perl versions with an outdated vendored zlib in Compress::Raw::Zlib contain multiple security issues that have been resolved in a specific commit. Lodash versions up to 4.17.23 contain multiple vulnerabilities including code injection via untrusted keys in _.template, prototype pollution, regex denial of service, and command injection. Apache HTTP Server versions 2.4.0 to 2.4.67 contain various vulnerabilities in multiple modules.

CSIRTS triage

What
A vulnerability allows unauthorized network access, potentially leading to full system takeover.
Who is affected
Deployments of Oracle Communications Converged Application Server versions 8.2 and 8.3.
Urgency
Remediation is urgent due to the high severity of the vulnerabilities, with some scoring 9 or higher.
Action
Apply the latest updates provided by Oracle.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Oracle Communications

Get an email when a new Oracle Communications advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0256

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-9900coverage & exploitation statusNVD · CVE.org
CVE-2025-31651coverage & exploitation statusNVD · CVE.org
CVE-2026-2332coverage & exploitation statusNVD · CVE.org
CVE-2026-4176coverage & exploitation statusNVD · CVE.org
CVE-2026-3381coverage & exploitation statusNVD · CVE.org
CVE-2026-27171coverage & exploitation statusNVD · CVE.org
CVE-2026-4800coverage & exploitation statusNVD · CVE.org
CVE-2021-23337coverage & exploitation statusNVD · CVE.org
CVE-2026-29167coverage & exploitation statusNVD · CVE.org
CVE-2026-33557coverage & exploitation statusNVD · CVE.org
CVE-2026-34520coverage & exploitation statusNVD · CVE.org
CVE-2026-39892coverage & exploitation statusNVD · CVE.org
CVE-2026-40976coverage & exploitation statusNVD · CVE.org
CVE-2026-42779coverage & exploitation statusNVD · CVE.org
CVE-2026-61223coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Oracle Communications

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories