NCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services
Oracle has resolved vulnerabilities in diverse Financial Services Enterprise modules. The vulnerabilities are present in Third Party products, such as Apache Kafka, Log4j and the Spring Framework, for which updates have previously been released by the developers. These updates are now incorporated by Oracle in the Financial Services modules that use these Third Party products. A malicious actor can exploit the vulnerabilities to gain access to sensitive data, cause a Denial-of-Service or execute arbitrary code on the vulnerable system.
CSIRTS triage
- What
- Vulnerabilities in third-party components (Apache Kafka, Log4j, Spring Framework) incorporated in Oracle Financial Services modules allow code execution, data disclosure, and denial-of-service.
- Who is affected
- Deployments of Oracle Financial Services modules using vulnerable third-party libraries.
- Urgency
- Medium to high severity with potential code execution and data access risk; apply Oracle patches promptly.
- Action
- Apply Oracle Financial Services security updates that incorporate third-party patches.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Financial Services Enterprise
Get an email when a new Financial Services Enterprise advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0312
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-335570.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-339290.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344810.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-418550.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-709220.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-33557 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33929 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34481 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41855 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70922 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Managerncsc-nl
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Financial Services Applications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Hyperion: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Retail Applications: Vulnerability compromises integritycert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- highCVE-2026-70922: Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Fi…nvd
- medium[UPDATE] [medium] Apache Kafka: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- high[UPDATE] [high] VMware Tanzu Spring Framework: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise2026-08-19
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Or…2026-08-19
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Manager2026-08-19