# Oracle patches critical Enterprise Manager flaws

Published: 2026-09-16 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/4d684921-8ce5-52f5-84c8-ee07b24682fd/oracle-patches-critical-enterprise-manager-flaws

> NCSC-NL warns of 7 Oracle Enterprise Manager vulnerabilities, three critical and unauthenticated-remotely-exploitable, urging priority patching.

NCSC-NL published an advisory detailing seven vulnerabilities patched by Oracle across Enterprise Manager Base Platform, Enterprise Manager for Fusion Middleware, and Enterprise Manager for Oracle Database. The flaws span improper output encoding, certificate validation issues (including host mismatch), missing authentication for a critical function, HTTP request smuggling, and deserialization of untrusted data. Five of the seven can be exploited remotely without authentication, and CVSS scores range from medium to critical.

Three vulnerabilities are rated critical (CVSS 9.1+): CVE-2026-41635 (CVSS 9.8) and CVE-2026-83355 (CVSS 9.8) affect the Agent Next Gen component of Enterprise Manager Base Platform and the Metrics component of Enterprise Manager for Fusion Middleware respectively, while CVE-2026-2332 (CVSS 9.1) affects the Oracle Management Service (OMS) of Enterprise Manager Base Platform. All three require low attack complexity and no user interaction, and can be exploited remotely without authentication, potentially resulting in high impact to confidentiality, integrity, and availability of affected systems.

No evidence of active in-the-wild exploitation is mentioned in the advisory. NCSC-NL recommends prioritizing deployment of the security updates for the three critical vulnerabilities. Affected organizations should inventory Enterprise Manager deployments (Base Platform, Fusion Middleware, and Oracle Database management components) and apply Oracle's official patches promptly; client-only installations without Enterprise Manager installed are not affected.

## Mentioned in this report

- Vulnerabilities: CVE-2025-68161, CVE-2026-2332, CVE-2026-41635, CVE-2026-49844, CVE-2026-62597, CVE-2026-83068, CVE-2026-83355

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0377.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4d684921-8ce5-52f5-84c8-ee07b24682fd/oracle-patches-critical-enterprise-manager-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
