NCSC-2026-0307 [1.00] [M/H] Vulnerabilities resolved in Oracle Database Products
Oracle has resolved vulnerabilities in diverse Database products such as the Database Server, Essbase, Autonomous Health Framework and the Application Testing Suite. Oracle Database Server (versions 19.3 through 23.26.3) contains critical vulnerabilities in the RDBMS and Portable Clusterware components, including possibilities for unauthenticated attackers with physical or network access to gain control over clusterware, obtain complete control over the RDBMS, or perform unauthorized read and write operations. Some vulnerabilities require physical access to communication segments, others can be exploited via network access. Oracle Essbase has vulnerabilities that enable an attacker with network access via HTTP to achieve complete system compromise. Oracle Autonomous Health Framework contains multiple vulnerabilities in the Trace File Analyzer and Cluster Health Analyzer components, which enable unauthorized access, data manipulation and denial of service, depending on privileges and network access. Oracle Application Testing Suite version 13.3.0.1 contains diverse vulnerabilities that enable unauthenticated or low-privileged attackers with network access via HTTP(S) to create, modify or delete critical data, escalate privileges and achieve complete system compromise. These vulnerabilities can lead to data breaches, data manipulation, denial of service and complete system compromise.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle Database products enable unauthenticated attackers to gain control over clusterware, achieve complete RDBMS control, perform unauthorized read/write operations, and achieve complete system compromise.
- Who is affected
- Oracle Database Server versions 19.3–23.26.3, Oracle Essbase, Oracle Autonomous Health Framework, and Oracle Application Testing Suite users.
- Urgency
- Critical; vulnerabilities enable unauthenticated remote code execution and complete system compromise via network or physical access.
- Action
- Apply Oracle's critical security patches for all affected Database products; prioritize systems running Database versions 19.3–23.26.3.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0307
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-95630.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-291670.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-427641.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 65% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-454475.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-598890.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-706880.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-706890.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-707150.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-707170.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-707280.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Keycloak: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0309 [1.00] [M/H] Vulnerabilities resolved in Oracle Communicationsncsc-nl
- high[NEW] [HIGH] Oracle Communications: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Oracle Database Server: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Database Server (August 19, 2026)cert-fr-avis
- criticalCVE-2026-71102: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versi…nvd
- mediumCVE-2026-71100: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd
- criticalCVE-2026-71064: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versi…nvd
- criticalCVE-2026-71063: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versi…nvd
- highCVE-2026-71062: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd
- highCVE-2026-70868: Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 1…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise2026-08-19
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Or…2026-08-19
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services2026-08-19