VORANT. Threat Intelligence Sign in Get the full feed

Oracle patches 31 flaws in Communications suite

high vulnerability telecommunications

Oracle fixed 31 vulnerabilities in its Communications product line, including four critical, unauthenticated remote flaws in Unified Assurance components.

NCSC-NL published an advisory summarizing Oracle's latest security update for its Communications portfolio, covering products including Oracle Communications Unified Assurance, Cloud Native Core Security Edge Protection Proxy, MetaSolv Solution Module - ASR, Service Catalog and Design, and Operations Monitor. The update addresses 31 vulnerabilities spanning a wide range of weakness classes: path traversal, symlink following, XSS, code injection, SSRF, open redirect, out-of-bounds write, improper certificate validation, incorrect authorization, and resource exhaustion issues, among others. CVSS scores range from low to critical, with 23 of the 31 flaws exploitable remotely without authentication.

Four vulnerabilities are rated critical (CVSS 9.1 or higher): CVE-2026-44024 (CVSS 9.8), CVE-2026-71290 and CVE-2026-73194 (both 9.1), and CVE-2026-17544 (CVSS v4 8.1, listed among the critical set). These reside in core third-party components bundled with Oracle Communications Unified Assurance — Fluentd, PHP, Apache HttpClient, and DBI — and can be exploited remotely without credentials, with high impact to confidentiality and, depending on the flaw, integrity and availability. Successful exploitation across the broader set of vulnerabilities could allow unauthorized access to sensitive data, data modification, or denial of service against affected systems. Some flaws require user interaction or prior access, while others are fully remote and unauthenticated.

NCSC-NL advises prioritizing deployment of patches for the four critical vulnerabilities. No in-the-wild exploitation is reported in this advisory; it is a standard vendor patch release covered by the national CERT. Defenders operating any of the named Oracle Communications products, which are widely used in telecom operator environments, should inventory affected versions and apply Oracle's official updates, referencing the CVE list for prioritization based on CVSS and remote/unauthenticated exploitability.

Mentioned in this report

Vulnerabilities CVE-2026-12590CVE-2026-13006CVE-2026-13758CVE-2026-17544CVE-2026-19880CVE-2026-34477CVE-2026-39822CVE-2026-41239CVE-2026-41989CVE-2026-44024CVE-2026-48998CVE-2026-49284CVE-2026-49844CVE-2026-50734CVE-2026-54518CVE-2026-55952CVE-2026-57220CVE-2026-58520CVE-2026-59943CVE-2026-61109CVE-2026-63308CVE-2026-64849KEVCVE-2026-66299CVE-2026-67355CVE-2026-71290CVE-2026-73194CVE-2026-73508CVE-2026-83417CVE-2026-83418CVE-2026-83419CVE-2026-9563

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0375.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free