MS-ISAC CYBERSECURITY ADVISORY – Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution – PATCH NOW

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

THREAT INTELLIGENCE:
There are currently no reports of these vulnerabilities being exploited in the wild.

SYSTEMS AFFECTED:

  • Helidon, versions 3.0.0-3.2.20, 4.0.0-4.5.4
  • Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.0.0, 14.1.2.1.0
  • Oracle Agile Engineering Data Management, version 6.2.1
  • Oracle Agile PLM, version 9.3.6
  • Oracle Agile PLM MCAD Connector, version 3.6
  • Oracle Application Testing Suite, version 13.3.0.1
  • Oracle Autonomous Health Framework, versions 26.2, 26.3.1, 26.5.3, 26.8
  • Oracle Banking Branch, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Corporate Lending, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Origination, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Treasury Management, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle BI Publisher, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0
  • Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0
  • Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy, versions 25.2.201, 26.1.200
  • Oracle Communications MetaSolv Solution Module – ASR, version 70.0.0
  • Oracle Communications Operations Monitor, version 6.1
  • Oracle Communications Service Catalog and Design, versions 8.0-8.3
  • Oracle Communications Unified Assurance, versions 6.1.1-7.0.0
  • Oracle Data Integrator, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Database Server, versions 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3
  • Oracle E-Business Suite, versions 12.2.3-12.2.15, V16
  • Oracle Enterprise Manager Base Platform, versions 13.5, 24.1
  • Oracle Enterprise Manager for Fusion Middleware, versions 13.5, 24.1
  • Oracle Enterprise Manager for Oracle Database, version 24.1
  • Oracle Forms, versions 12.2.1.19.0, 14.1.2.0.0
  • Oracle Fusion Middleware Control, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle GraalVM Enterprise Edition, version 21.3.19.1
  • Oracle GraalVM for JDK 17, version 23.0.13.1
  • Oracle GraalVM for JDK 21, version 23.1.12.1
  • Oracle Hyperion Data Relationship Management, version 11.2.26.0.0
  • Oracle Hyperion Financial Management, version 11.2.26.0.0
  • Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Internet Directory, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle JDeveloper, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Middleware Common Libraries and Tools, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • Oracle Platform Security for Java, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Product Lifecycle Analytics, version 3.6.1
  • Oracle Utilities Network Management System, versions 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 25.12.0.0.0-25.12.0.0.3
  • Oracle VM VirtualBox, version 7.2.16
  • Oracle Web Services Manager, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • PeopleSoft Enterprise CC Common Application Objects, version 9.2
  • PeopleSoft Enterprise FIN Engineering Brazil, version 9.1
  • PeopleSoft Enterprise FIN Inventory Brazil, version 9.1
  • PeopleSoft Enterprise PeopleTools, versions 8.61-8.63
  • PeopleSoft Enterprise PRTL Interaction Hub, version 9.1
  • Service Delivery Platform, versions 12.2.1.4.0, 14.1.2.0.0
  • Siebel Applications, versions 17.0-26.7

RISK:
Government:

  • Large and medium government entities: High
  • Small government: High

Businesses:

  • Large and medium business entities: High
  • Small business entities: High

Home Users: Low

TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution.

A full list of all vulnerabilities can be found in the Oracle link in the References section.

Successful exploitation of the most severe of these vulnerabilities could result in remote code execution in the context of the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

RECOMMENDATIONS:
We recommend the following actions be taken:

  • Apply appropriate updates provided by Oracle to vulnerable systems immediately after appropriate testing. (M1051:Update Software)
    • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 7.2: Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
    • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
    • Safeguard 7.5 : Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
    • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
    • Safeguard 12.1: Ensure Network Infrastructure is Up-to-Date: Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
    • Safeguard 18.1: Establish and Maintain a Penetration Testing Program: Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.
    • Safeguard 18.2: Perform Periodic External Penetration Tests: Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.
    • Safeguard 18.3: Remediate Penetration Test Findings: Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.
  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026:Privileged Account Management)
    • Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
    • Safeguard 5.4: Restrict Administrator Privileges to Dedicated Administrator Accounts: Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
    • Safeguard 5.5: Establish and Maintain an Inventory of Service Accounts: Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050:Exploit Protection)
    • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
  • Block execution of code on a system through application control, and/or script blocking. (M1038:Execution Prevention)
    • Safeguard 2.5: Allowlist Authorized Software: Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.
    • Safeguard 2.6: Allowlist Authorized Libraries: Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, .so, etc., files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.
    • Safeguard 2.7: Allowlist Authorized Scripts: Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1, .py, etc., files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.
  • Use capabilities to prevent suspicious behavior patterns from occurring on endpoint systems. This could include suspicious process, file, API call, etc. behavior. (M1040:Behavior Prevention on Endpoint)
    • Safeguard 13.2: Deploy a Host-Based Intrusion Detection Solution: Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
    • Safeguard 13.7: Deploy a Host-Based Intrusion Prevention Solution: Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
  • Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. (M1017:User Training)
    • Safeguard 14.1: Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 14.2: Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.


REFERENCES:

Oracle:
https://www.oracle.com/security-alerts/cspusep2026.html

Using AI for CSF 2.0 Analysis and Reporting—New NIST CSF Quick-Start Guide

NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and Reporting. This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.  

The document’s purpose is to: 

  • Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes 
  • Identify current state of practice for AI prompt engineering in CSF implementation and analysis 

While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\ notation.   

This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more.  

  • USE CASE 1 illustrates the use of an AI-assisted review to evaluate organization cybersecurity policy, strategy, and risk governance in alignment with the CSF 2.0 outcomes.  
  • USE CASE 2 illustrates how to produce a draft Organization Current State Profile– mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence.  
  • USE CASE 3 illustrates how to draw upon internal and industry references to create a draft CSF target state profile describing desired outcomes to meet mission objectives, stakeholder expectations, address the risk landscape, and fulfill requirements. 

Use case examples illustrate a possible approach and are not prescriptive assessment or assurance methodologies.  

Submit Your Comments:  

The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf@nist.gov.    

View and Comment

Multi-Cloud Architecture Challenges: Draft IR 8613 Available for Public Comment

NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security Public Working Group (MCSPWG) addresses security and Authorization to Operate (ATO) challenges and highlights areas where additional community research could meaningfully reduce risk.

The MCSPWG identified 23 consolidated challenge areas that represent novel friction points and architectural misalignments that emerge when orchestrating control across autonomous cloud silos. The most significant structural challenge areas are:

  • Security-significant differences in cloud-native services across providers
  • Organizational logistics and staffing complexity across heterogeneous environments
  • Difficulty in implementing centralized security capabilities across provider boundaries

These structural gaps are most acute in five areas: (1) identity and access management, (2) telemetry and logging, (3) configuration and change management, (4) data protection, and (5) compliance and authorization.

Submit Your Comments:

NIST invites input from federal agencies, industry partners, researchers, and the broader cybersecurity community. The public comment period is open through October 5, 2026. See the publication details for a copy of the draft and instructions for submitting comments.

Read More

Comment Now: Initial Non-Access Stratum Message Security White Paper

The NIST National Cybersecurity Center of Excellence (NCCoE) released the initial public draft Cybersecurity White Paper (CSWP) 36F, Initial Non-Access Stratum (NAS) Message Security, which describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.

You still have two weeks left to submit your feedback!

This white paper is part of the NCCoE’s work to accelerate the adoption of 5G security features by demonstrating their implementation on our operational 5G security testbed and providing actionable implementation guidelines to help network operators enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.

Background

Current 5G standards include specifications to address cybersecurity and privacy challenges present in previous generations of cellular systems. In 4G, the initial handshake message used to establish a connection between the device and the network—the Initial NAS Message—was sent without encryption or integrity protection. This leaves the 4G user device and the core network vulnerable to man-in-the-middle attacks.

Current 5G specifications allow the device to send the security-sensitive contents of the initial NAS message in an encrypted and integrity protected form.

This white paper describes how the NCCoE demonstrated these capabilities and explains how organizations can verify these protections in deployed 5G networks to protect the security and privacy on their networks.

By demonstrating security features on our operational 5G Testbed, we aim to deliver real-world implementation insights to advance 5G security and inform the next generation of wireless security. 

Submit Your Feedback!

This white paper is available for public comment through September 7, 2026. Don’t miss your chance to provide feedback! Visit the NCCoE project page to learn more and download the White Paper today.

Comment Now

Using Informative References for Cybersecurity Risk Management

The final version of NIST Special Publication (SP) 1347, Cybersecurity Framework (CSF) 2.0 Informative References Quick-Start Guidehas published. Thank you to all who provided comments during the public comment period.  

This publication explains what informative references are and how they support achieving the outcomes of the CSF 2.0. The guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement. 

View the Quick-Start Guide

You’re Invited: ITL AI Program Hosted Webinar on Development of an AI Agent Enrichment Workflow at the National Vulnerability Database

You’re invited to join NIST on September 17, 2026 for an Information Technology Laboratory (ITL) AI Program hosted webinar on the development of an AI agent enrichment workflow at the National Vulnerability Database.  

  • Workshop Title: Development of an AI Agent Enrichment Workflow at the National Vulnerability Database
  • When: Thursday, September 17, 2026 | 11:00 am – 12:00 pm Eastern Time 
  • Where: Virtual (Register

The National Vulnerability Database (NVD), established and operated by NIST, serves as the U.S. government repository of standards-based vulnerability management data. The NVD is a foundational resource for vulnerability management, software security, compliance automation, and cybersecurity risk analysis across the public and private sectors. It provides standardized vulnerability enrichment and associated metadata consumed by a broad ecosystem of security tools and operational workflows. It is a part of the broader vulnerability management ecosystem that encompasses processes, standards, and tools involved in one or more phases of the vulnerability lifecycle of identifying, validating, disclosing, disseminating, prioritizing, and remediating software and system vulnerabilities.

The increasing scale and complexity of discovered vulnerabilities poses a challenge for the NVD to provide timely information that is actionable to users of NVD data. The increasing use of AI tools to aid in the discovery and exploitation of vulnerabilities contributes even more to the job that is required to keep pace with the flow of publicly disclosed vulnerabilities.

To solve this, NIST has begun work on an AI agentic workflow to aid in the enrichment of vulnerability information provided by NVD. 

Join NIST to discuss the approach taken, the architecture of the solution, the various issues discovered during implementation, and early results with the use of the tool at the NVD.

Learn More and Register

Supply Chain Traceability & Manufacturing Meta-Framework Webinar

Join the NIST National Cybersecurity Center of Excellence (NCCoE) on September 29, 2026 at 1:00 P.M. EDT for a webinar to further explore the newly available NIST Supply Chain Traceability and Manufacturing Meta-Framework!

You still have two weeks left to register for this event! Secure your spot today.

Background

The NCCoE is helping to advance supply chain traceability by addressing one of the greatest barriers to effective supply chain risk management: securely verifying product pedigree and provenance across complex, multi-tier supply chains. Earlier this month, the NCCoE published the finalized version of NIST IR 8536, Supply Chain Traceability Principles: A Manufacturing Meta-Framework.

The Meta-Framework introduced in this report details a practical, conceptual approach for organizing, linking, and querying traceability data across diverse manufacturing supply chain ecosystems.

This webinar will explore:

  • The Traceability Challenge: An overview of the barriers to verifying product provenance across fragmented ecosystems, illustrated through a simplified discrete manufacturing supply chain use case example.
  • Core Principles for SCRM Support: A review of the foundational traceability principles necessary to inform organizational Supply Chain Risk Management (SCRM) programs.
  • Architectural Mechanics: How these foundational principles are operationalized within the Meta-Framework using structural data patterns (such as encapsulation and standardized interfaces) to establish a continuous, cross-sector provenance chain.
  • Data Privacy and Verifiable Trust: The utilization of hash-based traceability links to securely exchange product history without requiring suppliers to expose sensitive intellectual property or internal trade secrets.

Register Today!

Reserve your virtual seat before it’s too late! Visit the NCCoE event page to learn more and register.Register Now!

NIST Releases NIST SP 800-171A, R3 Small Business Primer

NIST has published Special Publication (SP) 1352, Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171Ar3 (Revision 3) Small Business PrimerThis guide provides small business owners and operators with a high-level overview of SP 800-171Ar3, Assessing Security Requirements for Controlled Unclassified Information. The goal of the primer is to help the small business community understand foundational SP 800-171 assessment concepts and basic strategies for planning for an assessment.   

Who is this Guide For?  

This primer is for business leaders or employees who are tasked with managing the implementation of SP 800-171r3, including conducting self-assessments or preparing to work with external assessors.

View the Primer

Open Radio Access Networks (O-RAN) CSF Profile for Federal Agencies | Initial Draft of NIST IR 8623

Federal agencies that deploy an Open Radio Access Network (O-RAN) as part of their infrastructure must include that deployment in their risk management programs. This draft Cybersecurity Framework (CSF) 2.0 profile – NIST Interagency Report (IR) 8623 – describes how components that conform to the security specifications produced by the O-RAN ALLIANCE support various CSF 2.0 outcomes. It also includes references to O-RAN ALLIANCE-produced documents and other relevant guidelines that may help federal agency cybersecurity managers.

The public comment review period is open through November 2, 2026. See the publication details for a copy of the draft and instructions for submitting comments. Find additional information on the NIST Advanced Security Architectures for Next Generation Wireless project webpage.

Read More