# Multiple critical vulnerabilities in Oracle Database Server Net Service allow remote code…

Published: 2026-05-29 · Severity: critical
Canonical: https://vorant.io/reports/190576d2-9410-4c9c-92a7-2ba7cf1d8ee7/multiple-critical-vulnerabilities-in-oracle-database-server-net-service-allow

> Multiple critical vulnerabilities in Oracle Database Server Net Service allow remote code execution and denial of service, affecting versions 23.4.0 through 23.26.2.

The French CERT (CERT-FR) has disclosed multiple vulnerabilities in Oracle Database Server's Net Service component affecting versions 23.4.0 through 23.26.2. The vulnerabilities enable remote attackers to execute arbitrary code and trigger denial of service conditions without prior authentication.

Three CVEs have been assigned to these flaws: CVE-2026-46833, CVE-2026-46834, and CVE-2026-46835. Oracle has released patches as part of their Critical Patch Update for May 2026. The Net Service component is a core networking layer for Oracle Database, making these vulnerabilities particularly significant for enterprises running affected versions.

Organizations running Oracle Database Server versions in the affected range should prioritize patching according to Oracle's May 2026 security bulletin. The combination of remote code execution and denial of service capabilities without authentication presents a severe risk to database infrastructure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-46833, CVE-2026-46834, CVE-2026-46835

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0662

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/190576d2-9410-4c9c-92a7-2ba7cf1d8ee7/multiple-critical-vulnerabilities-in-oracle-database-server-net-service-allow.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
