NCSC-2026-0258 [1.00] [M/H] Vulnerabilities fixed in Oracle Financial Services
Oracle has fixed vulnerabilities in various Financial Services modules. Oracle has also processed updates for various third-party products. The vulnerabilities include code injection via malicious schemas in Apache Avro, unauthorized access to sensitive data in various Oracle products, and authorization bypasses in Spring Security. Furthermore, there are issues with improper handling of HTTP headers in Spring Security, improper validation of JWT tokens in Apache Kafka, and insecure session state management in Eclipse Jetty. There are also vulnerabilities that lead to denial-of-service via resource exhaustion in Apache Netty and urllib3. Some vulnerabilities can lead to full system compromise, unauthorized data modification, or leakage of sensitive information. Exploitation can occur via network access, HTTP requests, or processing specially crafted files or messages. For certain vulnerabilities, user interaction is required, while others can be exploited remotely and without authentication.
CSIRTS triage
- What
- The vulnerabilities include code injection and unauthorized access to sensitive data.
- Who is affected
- Users of various Oracle Financial Services modules.
- Urgency
- Remediation is important as some vulnerabilities can lead to full system compromise.
- Action
- Apply the latest updates for Oracle Financial Services modules.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Financial Services
Get an email when a new Financial Services advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0258
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2024-475613.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 87% of all scored CVEs.
- Low exploitation riskCVE-2025-330420.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2025-412480.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2025-412490.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2025-708730.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Moderate exploitation riskCVE-2026-48002.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 84% of all scored CVEs.
- Elevated exploitation riskCVE-2021-2333721.3% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all scored CVEs.
- Low exploitation riskCVE-2026-57950.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Moderate exploitation riskCVE-2026-214412.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 84% of all scored CVEs.
- Low exploitation riskCVE-2026-227320.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Red Hat Enterprise Linux and Satellite (satellite/iop-remediations-rhel9 container image): Mul…cert-bund
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- high[UPDATE] [high] Red Hat Enterprise Linux (urllib3): Multiple vulnerabilities allow denial of servicecert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
- unknownNCSC-2026-0256 [1.00] [M/H] Vulnerabilities fixed in Oracle Communicationsncsc-nl
- high[NEW] [high] Oracle Siebel CRM: Multiple vulnerabilitiescert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30