


Perceptive Security
SOC/SIEM Consultancy

Oracle heeft een groot aantal kwetsbaarheden verholpen in verschillende Oracle middleware producten, waaronder Oracle Data Integrator, Oracle Coherence, Oracle …
Published:
22 July 2026 at 12:15:00
Alert date:
22 July 2026 at 16:08:55
Source:
ncsc.nl
Enterprise Applications, Web Technologies, Identity & Access, Zero-Day Vulnerabilities, Database & Storage
Oracle has patched 345 vulnerabilities across multiple Oracle Fusion Middleware products including Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform, and Oracle WebCenter Content. Nine vulnerabilities received the maximum CVSS score of 10.0, enabling unauthenticated remote attackers to achieve full system compromise. An additional 145 vulnerabilities scored between 9.0 and 9.9, many also exploitable without authentication. Attack vectors include HTTP, LDAP, SOAP and other network interfaces allowing arbitrary code execution without authentication. Some vulnerabilities may lead to unauthorized access, modification, or deletion of critical data, with potential cascading impact on dependent Oracle products. NCSC considers large-scale exploitation in the short term very likely and urges immediate patching.
Technical details
Mitigation steps:
Affected products:
Oracle Data Integrator
Oracle Coherence
Oracle Access Manager
Oracle Unified Directory
Oracle WebLogic Server Proxy Plug-in
Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler)
Oracle WebCenter Content
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
