VORANT. Threat Intelligence Sign in Get the full feed

Multiple critical vulnerabilities in Oracle Database Server Net Service allow remote code…

critical vulnerability

Multiple critical vulnerabilities in Oracle Database Server Net Service allow remote code execution and denial of service, affecting versions 23.4.0 through 23.26.2.

The French CERT (CERT-FR) has disclosed multiple vulnerabilities in Oracle Database Server's Net Service component affecting versions 23.4.0 through 23.26.2. The vulnerabilities enable remote attackers to execute arbitrary code and trigger denial of service conditions without prior authentication.

Three CVEs have been assigned to these flaws: CVE-2026-46833, CVE-2026-46834, and CVE-2026-46835. Oracle has released patches as part of their Critical Patch Update for May 2026. The Net Service component is a core networking layer for Oracle Database, making these vulnerabilities particularly significant for enterprises running affected versions.

Organizations running Oracle Database Server versions in the affected range should prioritize patching according to Oracle's May 2026 security bulletin. The combination of remote code execution and denial of service capabilities without authentication presents a severe risk to database infrastructure.

Mentioned in this report

Vulnerabilities CVE-2026-46833CVE-2026-46834CVE-2026-46835

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0662

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free