Multiples vulnérabilités dans Oracle Database Server (16 septembre 2026)
Multiple vulnerabilities have been discovered in Oracle Database Server, allowing for remote code execution and denial of service attacks. These vulnerabilities affect various versions of the database server and require immediate patching to mitigate the risk.
Oracle Database Server is experiencing a security vulnerability impacting multiple versions. The CERT-FR bulletin details several CVEs related to this issue. These vulnerabilities can be exploited to cause a denial of service and enable remote code execution. Affected versions include Oracle Database Server versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3. The specific CVE identifiers are CVE-2026-83088, CVE-2026-83156, CVE-2026-83160, CVE-2026-83271, CVE-2026-83272, CVE-2026-83333, CVE-2026-83347, CVE-2026-83348, CVE-2026-83349, and CVE-2026-83350. Users are advised to consult the Oracle Security Alerts bulletin for detailed information and to apply the necessary patches. The bulletin can be found at https://www.oracle.com/security-alerts/cspusep2026.html.