Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenHMD 106 Pure: Ultra-Simpel-Handy startet für nur rund 10 Euro(28.09.2026 um 19:22 Uhr)
•
IT NachrichtenGalaxy S25 Ultra One UI 9 Updates: The Beginning(28.09.2026 um 19:20 Uhr)
•
IT NachrichtenKiteworks lifts shutdown order after incident-free weekend(28.09.2026 um 15:21 Uhr)
•••••
IT NachrichtenSpaceX's latest Starship mission reached low-Earth orbit(28.09.2026 um 19:14 Uhr)
•••
IT Security NachrichtenHMD 106 Pure: Ultra-Simpel-Handy startet für nur rund 10 Euro(28.09.2026 um 19:22 Uhr)
•
IT NachrichtenGalaxy S25 Ultra One UI 9 Updates: The Beginning(28.09.2026 um 19:20 Uhr)
•
IT NachrichtenKiteworks lifts shutdown order after incident-free weekend(28.09.2026 um 15:21 Uhr)
•••••
IT NachrichtenSpaceX's latest Starship mission reached low-Earth orbit(28.09.2026 um 19:14 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware

Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion M…

0
↗ Quelle (csoonline.com)
Reagiere als Erste:r — dein Feedback zählt!








Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware.





Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials. Ten of them scored a “perfect” 10.0 on the Common Vulnerability Scoring System (CVSS).





These included easily exploitable vulnerabilities allowing unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, Oracle Access Manager, Oracle HTTP Server, Oracle Platform Security for Java, Oracle WebCenter Content, Service Delivery Platform, or Oracle Weblogic Server Proxy Plug-in,





No other products were found to have quite such extreme vulnerabilities, but there were plenty of others scoring almost as badly.





Two critical flaws in Oracle Database Server





The most severe flaw Oracle patched in its flagship database product is CVE-2026-61211, a vulnerability in the RDBMS component’s DBMS_CLOUD package with a CVSS score of 9.9.





This easily exploitable vulnerability allows a low-privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise the RDBMS, Oracle said in the patch update statement. “While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS,” it warned.





The flaw affects Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.





Sanchit Vir Gogia, chief analyst at Greyhound Research, said the 9.9 score should be read as serious but conditional. Exposure depends on configuration, he said: On customer-managed databases, DBMS_CLOUD is absent until installed, and grants and network access lists determine the radius from there. “Where DBMS_CLOUD is broadly granted and reachable, the emergency is real and the window is seventy-two hours; where it is absent, the accelerated database wave will do.”





Vibhum Dubey, a cybersecurity researcher and red teamer, said the flaw stood out to him because it checks several boxes that concern defenders.





“Database servers often hold an organization’s most valuable data, so even if exploitation is not publicly observed yet, I don’t think this is the kind of issue you leave until the next routine maintenance window if your environment is exposed,” Dubey said.





A second Database Server flaw, CVE-2026-47040, affects Connection Manager in Oracle Net Services, is remotely exploitable without credentials. Oracle’s risk matrix lists six Database Product vulnerabilities in this cycle as reachable over a network with no authentication required, the statement added.





CVE-2026-7383, an OpenSSL-related TLS vulnerability, affects two products, Database Server and Autonomous Health Framework, since both bundle the same third-party component. Oracle’s advisory notes the Database Server patch for that CVE also resolves 19 related OpenSSL CVEs bundled into the same fix.





Oracle GoldenGate received 27 new patches, nine of which do not require authentication to exploit, including CVE-2026-2332, a flaw in the Big Data and Application Adapters component tied to Eclipse Jetty, the statement added.





There were also two critical flaws in Oracle’s TimesTen in-memory database.





The remainder of the release spans E-Business Suite, WebLogic Server, PeopleSoft, Siebel, JD Edwards, Communications, Retail Applications, Utilities Applications, MySQL, Solaris and VM VirtualBox.





Volume repair





Gogia said the volume itself marks a shift.





“At 1,449 patches, against 481 in April 2026 and 309 a year earlier, patch load has outgrown the queue built to hold it,” he said. He recommended a tiered response: “The reachable and the reported inside seventy-two hours, the trusted core inside ten days, the rest by risk before the October release.”





He also flagged a specific risk in how organizations might triage E-Business Suite. “Oracle’s advisory concedes that E-Business Suite exposure sits partly in underlying Database and Fusion Middleware versions outside the E-Business Suite matrix. The fastest way to mis-prioritise this release is to patch by product logo instead of trust boundary.”





Third Tuesday, quarterly cycle





The July release is the third quarterly Critical Patch Update of 2026, and the first since the introduction in May of the monthly Critical Security Patch Update program.





Gogia said Oracle has effectively layered a second cadence on top of the existing one rather than replacing it.





“Quarterly Critical Patch Updates remain and stay cumulative; monthly Critical Security Patch Updates now sit on top,” he said, adding that enterprise adoption of the new rhythm remains low because of “certification obligations, regression exposure and scarce specialist hours.”





Dubey made a similar point about organizational readiness: “In large enterprises, patching is rarely a technical problem. It is an operational one. Database administrators, application owners, infrastructure teams, business stakeholders, and change advisory boards all have to align.”





Niyati Daftary, principal analyst at Gartner, said the release underscores a broader shift in how patching is approached.





“Patching is no longer a race to remediate every vulnerability. It is a discipline of identifying the exposures that matter most and reducing business risk as efficiently as possible,” she said, adding that organizations should prioritize based on exposure, business impact and exploitability, starting with internet-facing assets and mission-critical systems.





Daftary pointed to continuous threat exposure management and adversarial exposure validation as increasingly relevant frameworks, since CVSS scores “measure theoretical severity rather than actual enterprise risk.” Patching alone will not be sufficient, Daftary said, and organizations should continue investing in defense in depth, including behavioral threat detection and incident response.





Oracle’s next cumulative Critical Patch Update will come on Oct. 20, 2026, with smaller Critical Security Patch Updates on Aug. 18 and Sept. 15.


2. Cyber Threat Intelligence & Forensik

IoC Intelligence (4 Indikatoren)
CVE-2026-61211CVE-2026-47040CVE-2026-7383CVE-2026-2332
CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2026-2332
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
CRITICAL WEAPONIZED · Index 75/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
0-Click
Authentifizierung
Nicht erforderlich

3. Compliance, SLA & Vendor Adherence

CVSS 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Impact: 5.18 | Exploitability: 2.22
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACH
Hoch (High)
Erfordert Vorwissen, spezifische Zeitfenster oder unzuverlässige Race Conditions.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IH
Hoch (Volle Manipulation)
Vollständige Modifikation von Dateien, Parametern oder Ausführung von Code.
AN
Keine
Teilweise oder keine Beeinträchtigung.
BSI-Warnung (Deutschland)CVE-2026-61211
Oracle Database Server: Mehrere Schwachstellen21.07.2026
CISA-SSVC-Triage (vulnrichment)CVE-2026-61211
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-07-22T18:29:26.013047Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

Offizielles Hersteller-Update verfügbar
Handlungsempfehlung für Administratoren

Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware

Thematisch verwandte Begriffe: Oracles, July, update, fixes · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-101073 | A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impac…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag