# Oracle Database Server multiple vulnerabilities patched

Published: 2026-08-19 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/dfb772b8-9241-5314-b1f9-8386ba461f8a/oracle-database-server-multiple-vulnerabilities-patched

> ANSSI advisory details multiple Oracle Database Server flaws enabling remote code execution, denial of service, and data compromise.

CERT-FR has issued an advisory covering multiple vulnerabilities affecting Oracle Database Server versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3. The flaws stem from Oracle's August 2026 Critical Patch Update (cspuaug2026) and collectively allow an attacker to achieve remote code execution, remote denial of service, and unauthorized access to or disclosure of sensitive data, as well as impacts on data integrity.

Six CVEs are referenced in the bulletin without further technical detail provided in this advisory. No public exploitation, proof-of-concept, or threat actor activity is mentioned. Organizations running affected Oracle Database Server versions should consult Oracle's official security alert for patch details and apply updates according to their standard change-management procedures.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59889, CVE-2026-71062, CVE-2026-71063, CVE-2026-71064, CVE-2026-71100, CVE-2026-71102

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1047

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/dfb772b8-9241-5314-b1f9-8386ba461f8a/oracle-database-server-multiple-vulnerabilities-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
