CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0307 [1.00] [M/H] Vulnerabilities resolved in Oracle Database Products

unknownCVE-2026-9563CVE-2026-29167CVE-2026-42764CVE-2026-45447CVE-2026-59889CVE-2026-70688
Oracle has resolved vulnerabilities in diverse Database products such as the Database Server, Essbase, Autonomous Health Framework and the Application Testing Suite. Oracle Database Server (versions 19.3 through 23.26.3) contains critical vulnerabilities in the RDBMS and Portable Clusterware components, including possibilities for unauthenticated attackers with physical or network access to gain control over clusterware, obtain complete control over the RDBMS, or perform unauthorized read and write operations. Some vulnerabilities require physical access to communication segments, others can be exploited via network access. Oracle Essbase has vulnerabilities that enable an attacker with network access via HTTP to achieve complete system compromise. Oracle Autonomous Health Framework contains multiple vulnerabilities in the Trace File Analyzer and Cluster Health Analyzer components, which enable unauthorized access, data manipulation and denial of service, depending on privileges and network access. Oracle Application Testing Suite version 13.3.0.1 contains diverse vulnerabilities that enable unauthenticated or low-privileged attackers with network access via HTTP(S) to create, modify or delete critical data, escalate privileges and achieve complete system compromise. These vulnerabilities can lead to data breaches, data manipulation, denial of service and complete system compromise.

CSIRTS triage

vendor: OracleRemote code executionAuthentication bypassInformation disclosurePrivilege escalationMisconfigurationaffected: Database Server 19.3 through 23.26.3; Essbase and Autonomous Health Framework versions unspecified
What
Multiple vulnerabilities in Oracle Database products enable unauthenticated attackers to gain control over clusterware, achieve complete RDBMS control, perform unauthorized read/write operations, and achieve complete system compromise.
Who is affected
Oracle Database Server versions 19.3–23.26.3, Oracle Essbase, Oracle Autonomous Health Framework, and Oracle Application Testing Suite users.
Urgency
Critical; vulnerabilities enable unauthenticated remote code execution and complete system compromise via network or physical access.
Action
Apply Oracle's critical security patches for all affected Database products; prioritize systems running Database versions 19.3–23.26.3.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-19
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0307

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-9563coverage & exploitation statusNVD · CVE.org
CVE-2026-29167coverage & exploitation statusNVD · CVE.org
CVE-2026-42764coverage & exploitation statusNVD · CVE.org
CVE-2026-45447coverage & exploitation statusNVD · CVE.org
CVE-2026-59889coverage & exploitation statusNVD · CVE.org
CVE-2026-70688coverage & exploitation statusNVD · CVE.org
CVE-2026-70689coverage & exploitation statusNVD · CVE.org
CVE-2026-70715coverage & exploitation statusNVD · CVE.org
CVE-2026-70717coverage & exploitation statusNVD · CVE.org
CVE-2026-70728coverage & exploitation statusNVD · CVE.org
CVE-2026-70731coverage & exploitation statusNVD · CVE.org
CVE-2026-70734coverage & exploitation statusNVD · CVE.org
CVE-2026-70862coverage & exploitation statusNVD · CVE.org
CVE-2026-70863coverage & exploitation statusNVD · CVE.org
CVE-2026-70864coverage & exploitation statusNVD · CVE.org
CVE-2026-70865coverage & exploitation statusNVD · CVE.org
CVE-2026-70866coverage & exploitation statusNVD · CVE.org
CVE-2026-70867coverage & exploitation statusNVD · CVE.org
CVE-2026-70868coverage & exploitation statusNVD · CVE.org
CVE-2026-71062coverage & exploitation statusNVD · CVE.org
CVE-2026-71063coverage & exploitation statusNVD · CVE.org
CVE-2026-71064coverage & exploitation statusNVD · CVE.org
CVE-2026-71100coverage & exploitation statusNVD · CVE.org
CVE-2026-71102coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories