Skip to content
Beveiligingsnieuws

Critical Oracle Fusion Middleware vulnerabilities: act now

Update Oracle Fusion Middleware

The Netherlands National Cyber Security Centre (NCSC) issued an alert for critical Oracle Fusion Middleware vulnerabilities. According to the report, several very serious security issues were found across multiple Oracle Fusion Middleware products, and NCSC assesses the likelihood of misuse—and the potential damage—as high.

In this situation, waiting is risky. If you run affected components, the recommended next step is straightforward: install Oracle’s security updates as soon as possible.

What is Oracle Fusion Middleware used for?

Oracle Fusion Middleware is platform software that helps organizations connect applications and systems so they can work together. In practice, many businesses rely on it to support core business processes and to enable data exchange between environments and services.

Because it sits at the center of integration and operations, a compromise can impact more than one application at a time. That’s part of why critical weaknesses in these components deserve immediate attention.

Which products and CVEs are involved?

The alert highlights vulnerabilities in multiple Oracle Fusion Middleware products, including:

  • Oracle Data Integrator
  • Oracle Coherence
  • Oracle WebLogic Server

The NCSC specifically mentions vulnerabilities identified as CVE-2026-47056 and CVE-2026-60217. Both are assigned a maximum CVSS score of 10.0, which indicates critical severity.

Why these vulnerabilities are so dangerous

A key reason NCSC is urging fast action is the way these weaknesses can be exploited. The report states that an attacker can potentially target a system over the network without authentication—meaning no login credentials are required to attempt the attack.

Depending on the specific vulnerability, exploitation could enable an attacker to:

  • Execute malicious code
  • View sensitive data
  • Take over a system

When you combine remote reachability, no authentication requirement, and a CVSS score of 10.0, the risk profile becomes severe. NCSC therefore considers the probability of misuse high.

What could happen if an attacker succeeds?

If a system is successfully compromised, the consequences can extend across your organization. The NCSC alert describes outcomes such as:

  • System takeover
  • Viewing, modifying, or deleting data
  • Disruption of business processes
  • Loss of confidential information
  • Exposure of data to the wrong parties

Even if the initial goal is limited, attackers may escalate their access or pivot to other systems—especially in environments where middleware components connect multiple services.

What you should do now

Oracle has released security updates that address the reported vulnerabilities. NCSC advises installing these patches as quickly as possible.

If you manage middleware in multiple environments, treat patching as a priority across development, testing, and production—starting with the most critical systems first.

Step-by-step: patching and verification

  • Check what you run: confirm whether you use any affected Oracle Fusion Middleware components (including the products named in the alert).
  • Validate your versions: compare installed versions against what Oracle has patched.
  • Plan a safe rollout: schedule updates with maintenance windows where needed, and ensure backups or rollback plans are in place.
  • Install Oracle security updates: apply the available fixes without unnecessary delay.
  • Verify after installation: confirm services operate correctly and security controls behave as expected.

If you’re unsure whether any part of your stack is vulnerable, don’t guess—use your IT team or an external IT service provider to perform the check.

Need help determining exposure?

NCSC notes that if you don’t know whether your organization is running vulnerable versions, you should contact your IT service provider. The goal is to have your systems assessed for exposure, and then to apply the relevant security updates as soon as they’re available.

For organizations without strong asset inventories, this can also be a good moment to improve coverage: ensure middleware components, modules, and dependencies are tracked consistently.

How to reduce risk beyond patching

While patching is the immediate priority, it can also help to strengthen protections around middleware—particularly because these weaknesses can be reached from the network without authentication.

Consider actions such as:

  • Restrict network exposure: limit access to middleware endpoints to only what’s necessary.
  • Harden access paths: review firewall rules, segmentation, and access control around the systems in scope.
  • Monitor for suspicious activity: look for unusual requests or behavior patterns that could indicate exploitation attempts.
  • Review incident readiness: ensure your detection and response procedures are ready in case exploitation is discovered.

These measures do not replace installing Oracle’s fixes, but they can help reduce the chance of successful attacks while you work through patch deployment.

Conclusion

The NCSC alert makes it clear that critical Oracle Fusion Middleware vulnerabilities require prompt action. With CVSS scores reaching 10.0 and with reported exploitation potential over the network without authentication, the risk of misuse is considered high.

Install Oracle’s security updates as soon as possible, verify whether your environment includes vulnerable versions, and involve your IT service provider if you need help assessing exposure. Acting quickly can help protect your systems, prevent data compromise, and keep business processes running.

Source: https://www.ncsc.nl/alerts/update-oracle-fusion-middleware-direct-vanwege-kritieke-kwetsbaarheden