CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-61223

criticalCVSS 9covered by 2 sourcesfirst seen 2026-07-21
Oracle has fixed vulnerabilities in Communications products and underlying third-party software. There are a total of 213 vulnerabilities, of which 67 are in Oracle products and 146 in third-party products for which updates have previously been released and are now included in these Oracle updates. The most severe vulnerabilities, 12 in total, have received a CVSS score of 9 or higher and are described below. 11 of these are in embedded third-party products. The remaining vulnerabilities have lower scores, and it is too extensive to include detailed information in this advisory. For this, the NCSC refers to the attached reference. Oracle Communications Converged Application Server versions 8.2 and 8.3 contain a vulnerability that allows unauthorized network access and can lead to full system takeover. Libtiff up to version 4.7.0 contains a write-what-where vulnerability and a stack-based buffer overflow that can be triggered by specially crafted TIFF files, potentially leading to code execution or crashes. Apache Tomcat versions 8.5.0 to 11.0.5 contain vulnerabilities that allow specially crafted HTTP requests to bypass rewrite rules and security constraints, potentially resulting in data disclosure, modification, or denial of service. Eclipse Jetty's HTTP/1.1 parser improperly processes chunked transfer encoding extensions with improperly closed quotes, allowing request smuggling and potentially leading to cache poisoning, access control bypass, and session hijacking. Perl versions with an outdated vendored zlib in Compress::Raw::Zlib contain multiple security issues that have been resolved in a specific commit. Lodash versions up to 4.17.23 contain multiple vulnerabilities including code injection via untrusted keys in _.template, prototype pollution, regex denial of service, and command injection. Apache HTTP Server versions 2.4.0 to 2.4.67 contain various vulnerabilities in multiple modules.

CSIRTS triage

What
A vulnerability allows unauthorized network access, potentially leading to full system takeover.
Who is affected
Deployments of Oracle Communications Converged Application Server versions 8.2 and 8.3.
Urgency
Remediation is urgent due to the high severity of the vulnerabilities, with some scoring 9 or higher.
Action
Apply the latest updates provided by Oracle.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-61223

Get an email if CVE-2026-61223 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-61223

CVE.org record

Embed the live status

CVE-2026-61223 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-61223 status](https://www.csirts.com/badge/CVE-2026-61223)](https://www.csirts.com/cve/CVE-2026-61223)