NCSC-2026-0257 [1.00] [M/H] Vulnerabilities fixed in Oracle Enterprise Manager
Oracle has fixed multiple vulnerabilities in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The vulnerabilities in Oracle Enterprise Manager Base Platform allow attackers to perform unauthorized read, write, create, delete, and modify actions on sensitive data via network access over HTTPS or HTTP without authentication or with low privileges. Some vulnerabilities allow for full system compromise, including executing arbitrary code and taking over the system. Other vulnerabilities may lead to partial denial-of-service conditions. The vulnerabilities are present in various components of the platform, such as Agent Next Gen, Metadata Plugin, and UI Framework. Exploitation may require the attacker to have network access and, in some cases, user interaction. The vulnerabilities exploit insufficient access control and improper security measures within the platform.
CSIRTS triage
- What
- The vulnerabilities allow unauthorized actions on sensitive data and may lead to full system compromise.
- Who is affected
- Users of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1.
- Urgency
- Remediation is critical due to the potential for full system compromise.
- Action
- Update to the latest version of Oracle Enterprise Manager.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Enterprise Manager
Get an email when a new Enterprise Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0257
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2014-36432.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 80% of all scored CVEs.
- Elevated exploitation riskCVE-2020-954717.8% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all scored CVEs.
- Low exploitation riskCVE-2025-89160.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2025-681610.76% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
- Low exploitation riskCVE-2026-469840.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-469850.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-469860.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-469870.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-469880.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-469890.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- low[UPDATE] [low] Apache log4j: Vulnerability allows information disclosurecert-bund
- high[NEW] [high] SAP Patch Day July 2026cert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (July 23, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Commerce: Multiple vulnerabilitiescert-bund
- highCVE-2026-47006: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Mana…nvd
- highCVE-2026-47005: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Mana…nvd
- highCVE-2026-47004: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Mana…nvd
- mediumCVE-2026-47003: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Mana…nvd
Recent advisories for Oracle Enterprise Manager
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund · 2026-07-22
- criticalCVE-2026-61207: Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (comp…nvd · 2026-07-21
- criticalCVE-2026-61204: Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft…nvd · 2026-07-21
- highCVE-2026-61086: Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (…nvd · 2026-07-21
- highCVE-2026-61077: Vulnerability in the PeopleSoft Enterprise SCM Mobile Inventory Management product of Oracle P…nvd · 2026-07-21
- criticalCVE-2026-61076: Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle Pe…nvd · 2026-07-21
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30