VORANT. Threat Intelligence Sign in Get the full feed

Oracle Patches Six Flaws in Banking Applications

routine vulnerability financial-services

NCSC-NL advisory: six high-severity vulnerabilities patched in Oracle Financial Services Applications, two exploitable remotely without authentication.

NCSC-NL published an advisory covering six vulnerabilities fixed by Oracle in multiple Oracle Financial Services Applications products, including Oracle Banking Branch, Oracle Banking Corporate Lending, Oracle Banking Origination, Oracle Banking Treasury Management, and Oracle Banking Corporate Lending Process Management. The flaws relate to improper encoding/escaping of output and improper handling of inconsistent special elements, which can enable unauthenticated or low-privileged attackers with network access to perform unauthorized actions.

Of the six CVEs, two can be exploited remotely without authentication. Successful exploitation could result in unauthorized access to sensitive information, data modification, and disruption of system availability. None of the vulnerabilities are rated critical, but several carry high CVSS scores, with the highest (8.0) affecting Oracle Banking Branch and Oracle Banking Corporate Lending. Impact depends on the specific flaw but can affect confidentiality, integrity, and availability significantly.

Oracle has released updates addressing all six vulnerabilities. There is no indication in this advisory of active exploitation in the wild. Defenders operating affected Oracle Financial Services Applications products should apply the vendor-supplied patches promptly, prioritizing the two remotely exploitable, unauthenticated flaws (CVE-2026-83081 and CVE-2026-87164, both CVSS 8.0) and reviewing network exposure of these banking systems.

Mentioned in this report

Vulnerabilities CVE-2026-34480CVE-2026-83080CVE-2026-83081CVE-2026-83206CVE-2026-83489CVE-2026-87164

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0378.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free