Threat Response - Critical Remote Code Execution in Oracle Fusion Middleware
Dutch follows English
Oracle has released critical security updates fixing 345 vulnerabilities in their Fusion Middleware products [1]. Nine of these vulnerabilities have the maximum severity score of 10.0 and allow attackers to take complete control of systems without needing a username or password. Due to the high number of severe vulnerabilities, we expect attackers to exploit these weaknesses quickly. If your organization uses Oracle Fusion Middleware products, you must apply the available updates urgently.
Description
Oracle has fixed 345 security vulnerabilities in their Fusion Middleware products. These products include Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler), and Oracle WebCenter Content [1].
Nine vulnerabilities received the highest possible severity score of 10.0 [1]. An additional 145 vulnerabilities scored between 9.0 and 9.9. Attackers can exploit most of these severe vulnerabilities remotely over the network without needing authentication. They can use common network protocols like HTTP, LDAP, or SOAP to attack vulnerable systems [2].
Impact
We estimate the impact of these vulnerabilities as HIGH.
Attackers exploiting these vulnerabilities can execute their own code on your systems, gain complete control over affected servers, access sensitive information, modify critical data, or delete important information. The compromise can spread to other Oracle products that depend on the affected Middleware components. This means one compromised system could lead to broader damage across your IT environment.
Risk
We estimate the risk of these vulnerabilities as HIGH.
The combination of maximum severity scores, the ability to exploit without authentication, and the widespread use of Oracle Fusion Middleware creates an extremely dangerous situation. Attackers actively search for unpatched Oracle systems, and these updates provide them with a roadmap of weaknesses to exploit. Additionally, The Netherlands Cyber Security Center (NCSC-NL) considers it highly likely that attackers will exploit these vulnerabilities on a large scale in the short term [2].
Mitigation
Oracle has released security updates that fix these vulnerabilities. You must apply these updates urgently to all affected Oracle Fusion Middleware systems. Please update your Oracle Fusion Middleware to the latest version to apply the patches for these vulnerabilities, especially the Critical Patch Updates. Due to the different products and versions, the latest version number will depend on the product. If in doubt, review the Oracle security advisories at the links below to identify which specific products and versions you need to update: https://www.oracle.com/security-alerts/cpujul2026.html.
What should you do?
Check immediately if your organization uses any of the affected Oracle Fusion Middleware products and version as listed in the risk matrices by Oracle: https://www.oracle.com/security-alerts/cpujul2026.html. If you do, we recommend applying patches immediately to patch to versions higher than the listed affected versions in the matrices, especially if the listed base score is higher than 9 (“Critical severity”).
What will Northwave do?
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can contact us by phone or send us an email if you would like additional information.
E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000
Disclaimer applies, see below.
Sources
[1] https://www.oracle.com/security-alerts/cpujul2026.html
[2] https://advisories.ncsc.nl/2026/ncsc-2026-0252.html
Oracle heeft kritieke beveiligingsupdates uitgebracht die 345 kwetsbaarheden verhelpen in hun Fusion Middleware-producten [1]. Negen van deze kwetsbaarheden hebben de maximale CVSS-score van 10.0 en stellen aanvallers in staat om volledige controle over systemen te verkrijgen zonder dat een gebruikersnaam of wachtwoord nodig is. Vanwege het grote aantal ernstige kwetsbaarheden verwachten wij dat aanvallers deze kwetsbaarheden snel zullen misbruiken. Als uw organisatie Oracle Fusion Middleware-producten gebruikt, raden wij aan de beschikbare updates met spoed te installeren.
Beschrijving
Oracle heeft 345 beveiligingskwetsbaarheden verholpen in hun Fusion Middleware-producten. Deze producten omvatten Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler) en Oracle WebCenter Content [1].
Negen kwetsbaarheden kregen de hoogst mogelijke CVSS-score van 10.0 [1]. Daarnaast kregen nog eens 145 kwetsbaarheden een CVSS-score tussen 9.0 en 9.9. Aanvallers kunnen de meeste van deze ernstige kwetsbaarheden op afstand via het netwerk misbruiken zonder authenticatie. Zij kunnen hiervoor veelgebruikte netwerkprotocollen zoals HTTP, LDAP of SOAP gebruiken om kwetsbare systemen aan te vallen [2].
Impact
Wij schatten de impact van deze kwetsbaarheden in als HOOG.
Aanvallers die deze kwetsbaarheden misbruiken, kunnen eigen code uitvoeren op uw systemen, volledige controle verkrijgen over getroffen servers, toegang krijgen tot gevoelige informatie, kritieke gegevens wijzigen of belangrijke informatie verwijderen. De compromittering kan zich bovendien verspreiden naar andere Oracle-producten die afhankelijk zijn van de getroffen Middleware-componenten. Dit betekent dat één gecompromitteerd systeem kan leiden tot bredere schade binnen uw IT-omgeving.
Risico
Wij schatten het risico van deze kwetsbaarheden in als HOOG.
De combinatie van maximale CVSS-scores, de mogelijkheid tot misbruik zonder authenticatie en het wijdverbreide gebruik van Oracle Fusion Middleware creëert een uiterst gevaarlijke situatie. Aanvallers zoeken actief naar niet-gepatchte Oracle-systemen en deze updates bieden hen informatie over zwakke plekken om te misbruiken. Daarnaast acht het Nationaal Cyber Security Centrum (NCSC-NL) het zeer waarschijnlijk dat aanvallers deze kwetsbaarheden op grote schaal zullen exploiteren op korte termijn [2].
Mitigatie
Oracle heeft beveiligingsupdates uitgebracht die deze kwetsbaarheden verhelpen. U dient deze updates met spoed toe te passen op alle getroffen Oracle Fusion Middleware-systemen. Werk uw Oracle Fusion Middleware bij naar de nieuwste versie om de patches voor deze kwetsbaarheden te installeren, met name de Critical Patch Updates. Vanwege de verschillende producten en versies is het meest recente versienummer afhankelijk van het product. Raadpleeg bij twijfel de Oracle-beveiligingsadviezen via de volgende link om vast te stellen welke specifieke producten en versies moeten worden bijgewerkt: https://www.oracle.com/security-alerts/cpujul2026.html.
Wat moet u doen?
Controleer onmiddellijk of uw organisatie gebruikmaakt van een van de getroffen Oracle Fusion Middleware-producten en versies zoals vermeld in de risicomatrices van Oracle: https://www.oracle.com/security-alerts/cpujul2026.html. Indien dit het geval is, raden wij aan om onmiddellijk patches toe te passen en te upgraden naar versies die hoger zijn dan de getroffen versies die in de matrices worden vermeld, met name wanneer de vermelde base score hoger is dan 9 ("Critical severity").
Wat zal Northwave doen?
Northwave houdt de ontwikkelingen omtrent deze kwetsbaarheid in de gaten. Als er belangrijke nieuwe informatie omtrent deze dreiging bekend wordt, stellen wij u hiervan op de hoogte. Als u behoefte heeft aan extra informatie zijn we zowel telefonisch als via email bereikbaar.
E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000
Disclaimer van toepassing, zie hieronder.
Bronnen
[1] https://www.oracle.com/security-alerts/cpujul2026.html
[2] https://advisories.ncsc.nl/2026/ncsc-2026-0252.html

