NCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Manager
Oracle has resolved multiple vulnerabilities in diverse Oracle Enterprise Manager components. The vulnerabilities in Oracle Enterprise Manager Base Platform and Oracle Enterprise Manager for Systems Infrastructure involve multiple issues where an attacker with low privileges and sometimes without authentication can gain complete control over the system via the network or with logon access, create, delete or modify data, and access sensitive information. Some vulnerabilities enable privilege escalation. The affected versions are 13.5 and 24.1 for Enterprise Manager products.
CSIRTS triage
- What
- Multiple vulnerabilities in Enterprise Manager Base Platform and Systems Infrastructure allow low-privilege or unauthenticated attackers to gain control, modify data, and escalate privileges.
- Who is affected
- Deployments of Oracle Enterprise Manager versions 13.5 and 24.1.
- Urgency
- Medium to high severity with network-accessible privilege escalation paths; prioritize patching.
- Action
- Apply Oracle security patches for Enterprise Manager 13.5 and 24.1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Enterprise Manager
Get an email when a new Enterprise Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0311
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-23321.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344810.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608220.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-612840.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-612860.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-612980.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-613000.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-706840.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-707370.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-2332 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34481 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60822 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61284 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61286 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61298 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61300 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70684 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70737 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- unknownMultiple vulnerabilities in IBM products (September 4, 2026)cert-fr-avis
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- medium[UPDATE] [medium] Eclipse Jetty: Vulnerability allows data manipulationcert-bund
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian productsncsc-nl
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Servicesncsc-nl
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Financial Services Applications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Hyperion: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Retail Applications: Vulnerability compromises integritycert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0341 [1.00] [M/H] Vulnerabilities patched in Google Chrome2026-09-04
- unknownNCSC-2026-0340 [1.00] [M/H] Vulnerabilities fixed in Aruba Networks ArubaOS-CX2026-09-03
- unknownNCSC-2026-0339 [1.00] [M/H] Vulnerabilities fixed in HPE Networking Fabric Composer2026-09-03
- unknownNCSC-2026-0338 [1.00] [M/H] Vulnerabilities fixed in Cisco Nexus 9000 Series, IOS XR Software and Secure Email2026-09-03
- unknownNCSC-2026-0337 [1.00] [H/H] Zero-Day vulnerabilities patched in SonicWall SMA1000 Appliance2026-09-02