NCSC-2026-0309 [1.00] [M/H] Vulnerabilities resolved in Oracle Communications
Oracle has resolved vulnerabilities in different Communications modules, including Oracle Communications Cloud Native Core Network Exposure Function, Oracle Commerce Guided Search and Oracle Communications Unified Inventory Management. The vulnerabilities include among others stack-based buffer overflows, improper input validation, prototype pollution, improper authorization, use-after-free, deserialization filter bypass, and insufficient access control. Attackers can exploit these vulnerabilities to among other things cause Denial of Service (DoS), obtain unauthorized access, modify or view sensitive data, perform arbitrary code execution, and achieve complete system compromise. Specifically, some vulnerabilities can lead to privilege escalation, authentication bypass, and remote code execution without authentication. The vulnerabilities are present in diverse versions of the mentioned products and modules, with some fixes already released in specific versions. Therefore, check whether the specific vulnerabilities apply to your own system.
CSIRTS triage
- What
- Multiple vulnerabilities including stack-based buffer overflows, improper input validation, prototype pollution, improper authorization, use-after-free, deserialization filter bypass, and insufficient access control in Oracle Communications modules.
- Who is affected
- Users of Oracle Communications Cloud Native Core Network Exposure Function, Oracle Commerce Guided Search, and Oracle Communications Unified Inventory Management across multiple affected versions.
- Urgency
- Critical; vulnerabilities enable unauthenticated remote code execution, privilege escalation, authentication bypass, and complete system compromise without authentication.
- Action
- Apply Oracle's security patches immediately for affected Communications modules; check Oracle Security Alert for specific version remediation details.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0309
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2025-131511.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-41760.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-48002.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 84% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2021-2333721.3% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-57950.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-291670.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-425870.99% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-427790.90% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-559561.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-590840.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-13151 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4176 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4800 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-23337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-5795 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-29167 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42587 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42779 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55956 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59084 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71142 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71143 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQLncsc-nl
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0307 [1.00] [M/H] Vulnerabilities resolved in Oracle Database Productsncsc-nl
- unknownNCSC-2026-0306 [1.00] [H/H] Vulnerabilities resolved in Oracle Fusion Middlewarencsc-nl
- high[NEW] [HIGH] Oracle Communications: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle MySQL: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- highCVE-2026-71143: Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Comm…nvd
- highCVE-2026-71142: Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Comm…nvd
- medium[UPDATE] [medium] Apache Tomcat: Multiple vulnerabilitiescert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise2026-08-19
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Or…2026-08-19
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services2026-08-19