NCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services
Oracle has resolved vulnerabilities in diverse Financial Services Enterprise modules. The vulnerabilities are present in Third Party products, such as Apache Kafka, Log4j and the Spring Framework, for which updates have previously been released by the developers. These updates are now incorporated by Oracle in the Financial Services modules that use these Third Party products. A malicious actor can exploit the vulnerabilities to gain access to sensitive data, cause a Denial-of-Service or execute arbitrary code on the vulnerable system.
CSIRTS triage
- What
- Vulnerabilities in third-party components (Apache Kafka, Log4j, Spring Framework) incorporated in Oracle Financial Services modules allow code execution, data disclosure, and denial-of-service.
- Who is affected
- Deployments of Oracle Financial Services modules using vulnerable third-party libraries.
- Urgency
- Medium to high severity with potential code execution and data access risk; apply Oracle patches promptly.
- Action
- Apply Oracle Financial Services security updates that incorporate third-party patches.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Financial Services Enterprise
Get an email when a new Financial Services Enterprise advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0312
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-335570.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-339290.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344810.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-418550.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-709220.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-33557 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33929 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34481 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41855 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70922 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Apache log4j: Mehrere Schwachstellen ermöglichen Manipulation von Dateiencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (04 septembre 2026)cert-fr-avis
- high[UPDATE] [high] IBM License Metric Tool: Multiple Vulnerabilities enable unspecified attackcert-bund
- high[UPDATE] [high] VMware Tanzu Spring Framework: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Managerncsc-nl
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Financial Services Applications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Hyperion: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Supply Chain: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Retail Applications: Vulnerability compromises integritycert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- highCVE-2026-70922: Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Fi…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12
- unknownNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions2026-09-12
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able2026-09-11