CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0309 [1.00] [M/H] Vulnerabilities resolved in Oracle Communications

unknownCVE-2025-13151CVE-2026-4176CVE-2026-4800CVE-2021-23337CVE-2026-5795CVE-2026-29167
Oracle has resolved vulnerabilities in different Communications modules, including Oracle Communications Cloud Native Core Network Exposure Function, Oracle Commerce Guided Search and Oracle Communications Unified Inventory Management. The vulnerabilities include among others stack-based buffer overflows, improper input validation, prototype pollution, improper authorization, use-after-free, deserialization filter bypass, and insufficient access control. Attackers can exploit these vulnerabilities to among other things cause Denial of Service (DoS), obtain unauthorized access, modify or view sensitive data, perform arbitrary code execution, and achieve complete system compromise. Specifically, some vulnerabilities can lead to privilege escalation, authentication bypass, and remote code execution without authentication. The vulnerabilities are present in diverse versions of the mentioned products and modules, with some fixes already released in specific versions. Therefore, check whether the specific vulnerabilities apply to your own system.

CSIRTS triage

What
Multiple vulnerabilities including stack-based buffer overflows, improper input validation, prototype pollution, improper authorization, use-after-free, deserialization filter bypass, and insufficient access control in Oracle Communications modules.
Who is affected
Users of Oracle Communications Cloud Native Core Network Exposure Function, Oracle Commerce Guided Search, and Oracle Communications Unified Inventory Management across multiple affected versions.
Urgency
Critical; vulnerabilities enable unauthenticated remote code execution, privilege escalation, authentication bypass, and complete system compromise without authentication.
Action
Apply Oracle's security patches immediately for affected Communications modules; check Oracle Security Alert for specific version remediation details.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-19
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0309

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-13151coverage & exploitation statusNVD · CVE.org
CVE-2026-4176coverage & exploitation statusNVD · CVE.org
CVE-2026-4800coverage & exploitation statusNVD · CVE.org
CVE-2021-23337coverage & exploitation statusNVD · CVE.org
CVE-2026-5795coverage & exploitation statusNVD · CVE.org
CVE-2026-29167coverage & exploitation statusNVD · CVE.org
CVE-2026-42587coverage & exploitation statusNVD · CVE.org
CVE-2026-42779coverage & exploitation statusNVD · CVE.org
CVE-2026-55956coverage & exploitation statusNVD · CVE.org
CVE-2026-59084coverage & exploitation statusNVD · CVE.org
CVE-2026-71142coverage & exploitation statusNVD · CVE.org
CVE-2026-71143coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories