Oracle patches 16 database product flaws
NCSC-NL advises priority patching of a critical Oracle Application Testing Suite flaw among 16 fixed Oracle Database vulnerabilities.
NCSC-NL published an advisory summarizing Oracle's fixes for 16 vulnerabilities across Database Server, Autonomous Health Framework, and Application Testing Suite products. CVSS scores range from medium to critical, with six flaws exploitable remotely without authentication. Successful exploitation could result in unauthorized access to sensitive data, data modification, or disruption of system availability, depending on the specific vulnerability.
The most severe issue, CVE-2026-83149 (CVSS 9.1), affects Test Manager for Web Apps within Oracle Application Testing Suite. It requires only a low-privileged account and no user interaction, and can lead to a high impact on confidentiality with limited impact on integrity and availability. NCSC-NL specifically recommends prioritizing the patch for this vulnerability.
No evidence of active exploitation is mentioned in the advisory. Defenders running affected Oracle Database products should apply the vendor-issued updates referenced in Oracle's security advisories, prioritizing systems running Application Testing Suite's Test Manager for Web Apps component, and review exposure for the six unauthenticated remotely exploitable flaws.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0373.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free