ENISA EUVD · EUVD-2026-22243Official EUVD mappingIn Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here:
* https://w4ke.info/2025/06/18/funky-chunks.html
* https://w4ke.info/2025/10/29/funky-chunks-2.html
Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error.
POST / HTTP/1.1
Host: localhost
Transfer-Encoding: chunked
1;ext="val
X
0
GET /smuggled HTTP/1.1
...
Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
Official EUVD record ↗BSI · German · WID-SEC-2026-3399Oracle Enterprise Manager: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Enterprise Manager ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-3220SAP Patch Day September 2026: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Berechtigungen zu erweitern, vertrauliche Informationen offenzulegen oder zu manipulieren, SQL-Injection-Angriffe durchzuführen oder einen Denial-of-Service-Zustand zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2026-2890Oracle Enterprise Manager: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Enterprise Manager ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2437Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-2260IBM Operational Decision Manager: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Operational Decision Manager ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-1720Oracle REST Data Services: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle REST Data Services ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-1082Eclipse Jetty: Schwachstelle ermöglicht Manipulation von DatenEin entfernter, anonymer Angreifer kann eine Schwachstelle in Eclipse Jetty ausnutzen, um Daten zu manipulieren.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260415Security Bulletin 15 April 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 15 April 2026, published on 15 April 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗INCIBE-CERT · Spanish · boletin-de-seguridad-de-atlassian-agosto-de-2026Boletín de seguridad de Atlassian: agosto de 2026n org.hibernate:hibernate-core-jakarta.
CVE-2026-67320: Divulgación de información en axios.
CVE-2026-54291: MITM (Man-in-the-Middle) en org.postgresql:postgresql.
CVE-2026-41907: RCE (Remote Code Execution) en uuid.
CVE-2026-41851: DoS (Denial of Service) en org.springframework:spring-expression.
CVE-2026-55831: DoS (Denial of Service) en io.netty:netty-codec-http.
CVE-2026-41850: DoS (Denial of Service) en org.springframework:spring-expression.
CVE
Identificador CVE
Severidad
Explotación
Fabricante
CVE-2021-44906
Crítica
No
ATLASSIAN
CVE-2025-14813
Crítica
No
ATLASSIAN
CVE-2026-59873
Crítica
No
ATLASSIAN
CVE-2026-53434
Crítica
No
ATLASSIAN
CVE-2026-2332
Crítica
No
ATLASSIAN
CVE-2026-4800
Crítica
No
ATLASSIAN
CVE-2023-45133
Crítica
No
ATLASSIAN
CVE-2026-59873
Crítica
No
ATLASSIAN
CVE-2026-4800
Crítica
No
ATLASSIAN
CVE-2026-59873
Crítica
No
ATLASSIAN
Listado de referencias
Security Bulletin - August 18 2026
Etiquetas
Actualización
Aviso
Criptografía
Denegación de servicio - DoS - DDoS
+
Inyección
RCE
Vulnerabilidad
-
Suscripción boletines
Nipo : 094-20-022-9
Síguenos en:
Contacto
Valora nuestros servicios
Empleo
Política de Privacidad
Aviso Legal
Accesibilidad
Configuración de cookies
Política de cookies
Mapa web
Transparencia
Perfil de contratante
Canal de denuncias
Nipo : 094-20-027-6
×
Ir
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-18401
Référence CVE CVE-2026-18446
https://www.cve.org/CVERecord?id=CVE-2026-18446
Référence CVE CVE-2026-18499
https://www.cve.org/CVERecord?id=CVE-2026-18499
Référence CVE CVE-2026-19880
https://www.cve.org/CVERecord?id=CVE-2026-19880
Référence CVE CVE-2026-22610
https://www.cve.org/CVERecord?id=CVE-2026-22610
Référence CVE CVE-2026-22740
https://www.cve.org/CVERecord?id=CVE-2026-22740
Référence CVE CVE-2026-22741
https://www.cve.org/CVERecord?id=CVE-2026-22741
Référence CVE CVE-2026-22745
https://www.cve.org/CVERecord?id=CVE-2026-22745
Référence CVE CVE-2026-22748
https://www.cve.org/CVERecord?id=CVE-2026-22748
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-2482
https://www.cve.org/CVERecord?id=CVE-2026-2482
Référence CVE CVE-2026-25639
https://www.cve.org/CVERecord?id=CVE-2026-25639
Référence CVE CVE-2026-27830
https://www.cve.org/CVERecord?id=CVE-2026-27830
Référence CVE CVE-2026-27970
https://www.cve.org/CVERecord?id=CVE-2026-27970
Référence CVE CVE-2026-28338
https://www.cve.org/CVERecord?id=CVE-2026-28338
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-2950
https://www.cve.org/CVERecord?id=CVE-2026-2950
Référence CVE CVE-2026-32990
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1134Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-22007
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=CVE-2026-22013
Référence CVE CVE-2026-22016
https://www.cve.org/CVERecord?id=CVE-2026-22016
Référence CVE CVE-2026-22018
https://www.cve.org/CVERecord?id=CVE-2026-22018
Référence CVE CVE-2026-22021
https://www.cve.org/CVERecord?id=CVE-2026-22021
Référence CVE CVE-2026-22752
https://www.cve.org/CVERecord?id=CVE-2026-22752
Référence CVE CVE-2026-22795
https://www.cve.org/CVERecord?id=CVE-2026-22795
Référence CVE CVE-2026-22796
https://www.cve.org/CVERecord?id=CVE-2026-22796
Référence CVE CVE-2026-2303
https://www.cve.org/CVERecord?id=CVE-2026-2303
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-2359
https://www.cve.org/CVERecord?id=CVE-2026-2359
Référence CVE CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
Référence CVE CVE-2026-2391
https://www.cve.org/CVERecord?id=CVE-2026-2391
Référence CVE CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2026-23950
Référence CVE CVE-2026-2482
https://www.cve.org/CVERecord?id=CVE-2026-2482
Référence CVE CVE-2026-24842
https://www.cve.org/CVERecord?id=CVE-2026-24842
Référence CVE CVE-2026-24880
https://www.cve.org/CVERecord?id=CVE-2026-24880
Référence CVE CVE-2026-25639
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2022-37601
Référence CVE CVE-2022-37603
https://www.cve.org/CVERecord?id=CVE-2022-37603
Référence CVE CVE-2025-11226
https://www.cve.org/CVERecord?id=CVE-2025-11226
Référence CVE CVE-2025-14813
https://www.cve.org/CVERecord?id=CVE-2025-14813
Référence CVE CVE-2025-62718
https://www.cve.org/CVERecord?id=CVE-2025-62718
Référence CVE CVE-2025-69873
https://www.cve.org/CVERecord?id=CVE-2025-69873
Référence CVE CVE-2026-12143
https://www.cve.org/CVERecord?id=CVE-2026-12143
Référence CVE CVE-2026-21577
https://www.cve.org/CVERecord?id=CVE-2026-21577
Référence CVE CVE-2026-21579
https://www.cve.org/CVERecord?id=CVE-2026-21579
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-29145
https://www.cve.org/CVERecord?id=CVE-2026-29145
Référence CVE CVE-2026-29146
https://www.cve.org/CVERecord?id=CVE-2026-29146
Référence CVE CVE-2026-33671
https://www.cve.org/CVERecord?id=CVE-2026-33671
Référence CVE CVE-2026-34043
https://www.cve.org/CVERecord?id=CVE-2026-34043
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-21441
Référence CVE CVE-2026-21860
https://www.cve.org/CVERecord?id=CVE-2026-21860
Référence CVE CVE-2026-22007
https://www.cve.org/CVERecord?id=CVE-2026-22007
Référence CVE CVE-2026-22008
https://www.cve.org/CVERecord?id=CVE-2026-22008
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=CVE-2026-22013
Référence CVE CVE-2026-22016
https://www.cve.org/CVERecord?id=CVE-2026-22016
Référence CVE CVE-2026-22018
https://www.cve.org/CVERecord?id=CVE-2026-22018
Référence CVE CVE-2026-22021
https://www.cve.org/CVERecord?id=CVE-2026-22021
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-23479
https://www.cve.org/CVERecord?id=CVE-2026-23479
Référence CVE CVE-2026-23490
https://www.cve.org/CVERecord?id=CVE-2026-23490
Référence CVE CVE-2026-2359
https://www.cve.org/CVERecord?id=CVE-2026-2359
Référence CVE CVE-2026-23631
https://www.cve.org/CVERecord?id=CVE-2026-23631
Référence CVE CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
Référence CVE CVE-2026-23865
https://www.cve.org/CVERecord?id=CVE-2026-23865
Référence CVE CVE-2026-2391
https://www.cve.org/CVERecord?id=CVE-2026-2391
Référence CVE CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBMrd?id=CVE-2026-1605
Référence CVE CVE-2026-22007
https://www.cve.org/CVERecord?id=CVE-2026-22007
Référence CVE CVE-2026-22008
https://www.cve.org/CVERecord?id=CVE-2026-22008
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=CVE-2026-22013
Référence CVE CVE-2026-22016
https://www.cve.org/CVERecord?id=CVE-2026-22016
Référence CVE CVE-2026-22018
https://www.cve.org/CVERecord?id=CVE-2026-22018
Référence CVE CVE-2026-22021
https://www.cve.org/CVERecord?id=CVE-2026-22021
Référence CVE CVE-2026-22795
https://www.cve.org/CVERecord?id=CVE-2026-22795
Référence CVE CVE-2026-22796
https://www.cve.org/CVERecord?id=CVE-2026-22796
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-23865
https://www.cve.org/CVERecord?id=CVE-2026-23865
Référence CVE CVE-2026-25680
https://www.cve.org/CVERecord?id=CVE-2026-25680
Référence CVE CVE-2026-25681
https://www.cve.org/CVERecord?id=CVE-2026-25681
Référence CVE CVE-2026-27136
https://www.cve.org/CVERecord?id=CVE-2026-27136
Référence CVE CVE-2026-33814
https://www.cve.org/CVERecord?id=CVE-2026-33814
Référence CVE CVE-2026-33870
https://www.cve.org/CVERecord?id=CVE-2026-33870
Référence CVE CVE-2026-33871
https://www.cve.org/CVERecord?id=CVE-2026-33871
Référence CVE CVE-2026-34268
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0698Multiples vulnérabilités dans les produits IBMRecord?id=CVE-2026-1527
Référence CVE CVE-2026-1528
https://www.cve.org/CVERecord?id=CVE-2026-1528
Référence CVE CVE-2026-22007
https://www.cve.org/CVERecord?id=CVE-2026-22007
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=CVE-2026-22013
Référence CVE CVE-2026-22016
https://www.cve.org/CVERecord?id=CVE-2026-22016
Référence CVE CVE-2026-22018
https://www.cve.org/CVERecord?id=CVE-2026-22018
Référence CVE CVE-2026-22021
https://www.cve.org/CVERecord?id=CVE-2026-22021
Référence CVE CVE-2026-22036
https://www.cve.org/CVERecord?id=CVE-2026-22036
Référence CVE CVE-2026-2229
https://www.cve.org/CVERecord?id=CVE-2026-2229
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-2359
https://www.cve.org/CVERecord?id=CVE-2026-2359
Référence CVE CVE-2026-24486
https://www.cve.org/CVERecord?id=CVE-2026-24486
Référence CVE CVE-2026-25645
https://www.cve.org/CVERecord?id=CVE-2026-25645
Référence CVE CVE-2026-25793
https://www.cve.org/CVERecord?id=CVE-2026-25793
Référence CVE CVE-2026-2581
https://www.cve.org/CVERecord?id=CVE-2026-2581
Référence CVE CVE-2026-26007
https://www.cve.org/CVERecord?id=CVE-2026-26007
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-2950
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0581Multiples vulnérabilités dans MongoDBDe multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0556Multiples vulnérabilités dans les produits VMwareord?id=CVE-2026-22022
Référence CVE CVE-2026-22701
https://www.cve.org/CVERecord?id=CVE-2026-22701
Référence CVE CVE-2026-22731
https://www.cve.org/CVERecord?id=CVE-2026-22731
Référence CVE CVE-2026-22732
https://www.cve.org/CVERecord?id=CVE-2026-22732
Référence CVE CVE-2026-22733
https://www.cve.org/CVERecord?id=CVE-2026-22733
Référence CVE CVE-2026-22735
https://www.cve.org/CVERecord?id=CVE-2026-22735
Référence CVE CVE-2026-22737
https://www.cve.org/CVERecord?id=CVE-2026-22737
Référence CVE CVE-2026-22815
https://www.cve.org/CVERecord?id=CVE-2026-22815
Référence CVE CVE-2026-2297
https://www.cve.org/CVERecord?id=CVE-2026-2297
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-23949
https://www.cve.org/CVERecord?id=CVE-2026-23949
Référence CVE CVE-2026-24049
https://www.cve.org/CVERecord?id=CVE-2026-24049
Référence CVE CVE-2026-24051
https://www.cve.org/CVERecord?id=CVE-2026-24051
Référence CVE CVE-2026-24281
https://www.cve.org/CVERecord?id=CVE-2026-24281
Référence CVE CVE-2026-24308
https://www.cve.org/CVERecord?id=CVE-2026-24308
Référence CVE CVE-2026-24880
https://www.cve.org/CVERecord?id=CVE-2026-24880
Référence CVE CVE-2026-25645
https://www.cve.org/CVERecord?id=CVE-2026-25645
Référence CVE CVE-2026-25679
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0500Multiples vulnérabilités dans VMware Tanzu/CVERecord?id=CVE-2026-1225
Référence CVE CVE-2026-1525
https://www.cve.org/CVERecord?id=CVE-2026-1525
Référence CVE CVE-2026-1526
https://www.cve.org/CVERecord?id=CVE-2026-1526
Référence CVE CVE-2026-1527
https://www.cve.org/CVERecord?id=CVE-2026-1527
Référence CVE CVE-2026-22036
https://www.cve.org/CVERecord?id=CVE-2026-22036
Référence CVE CVE-2026-2229
https://www.cve.org/CVERecord?id=CVE-2026-2229
Référence CVE CVE-2026-22732
https://www.cve.org/CVERecord?id=CVE-2026-22732
Référence CVE CVE-2026-22735
https://www.cve.org/CVERecord?id=CVE-2026-22735
Référence CVE CVE-2026-22737
https://www.cve.org/CVERecord?id=CVE-2026-22737
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
Référence CVE CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2026-23950
Référence CVE CVE-2026-24098
https://www.cve.org/CVERecord?id=CVE-2026-24098
Référence CVE CVE-2026-24733
https://www.cve.org/CVERecord?id=CVE-2026-24733
Référence CVE CVE-2026-24734
https://www.cve.org/CVERecord?id=CVE-2026-24734
Référence CVE CVE-2026-24842
https://www.cve.org/CVERecord?id=CVE-2026-24842
Référence CVE CVE-2026-25219
https://www.cve.org/CVERecord?id=CVE-2026-25219
Référence CVE CVE-2026-25639
https://www.cve.org/CVERecord?id=C
Official advisory ↗CSIRT Italia · Italian · sap-security-patch-day-20SAP Security Patch DayNel dettaglio, la vulnerabilità identificata tramite la CVE-2026-2332 , di tipo " HTTP Request/Response Smuggling " e con score pari a 7.4, è dovuta all'uso di componenti Jetty vulnerabili alla " CRLF Injection (Carriage Return Line Feed Injection) " che interessa i prodotti SAP Commerce Cloud (Search and Navigation). I caratteri CR e LF vengono utilizzati dai protocolli HTTP per delimitare righe e header. Quando un'applicazione non filtra correttamente input controllabili dall'utente, un attaccante può inserire CRLF all'interno di:
URL
parametri HTTP
header
richieste API
e modificare la struttura della risposta HTTP generata dal server.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-014259Eclipse FoundationのJettyにおけるHTTP リクエストスマグリングに関する脆弱性Eclipse Jettyにおいて、HTTP/1.1パーサーはチャンク拡張が使用された場合にリクエストスマグリングの脆弱性を引き起こします。これは、以下で説明されている「ファンキー・チャンク」技術に類似しています。* https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jettyはチャンク拡張の解析を引用符内の\r\nで終了させており、これをエラーとして扱いません。 例えば、次のようなリクエストがあります。 POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... この例では、チャンク拡張の二重引用符が閉じられていないことに注目してください。このため、スマグリングされたリクエストを注入できます。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0377Kwetsbaarheden verholpen in Oracle Enterprise ManagerDe kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Enterprise Manager-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 7 kwetsbaarheden zijn drie als kritiek aangemerkt en volgens Oracle kunnen vijf kwetsbaarheden zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het verkrijgen van ongeautoriseerde toegang tot gevoelige informatie, het wijzigen van gegevens en het verstoren van de beschikbaarheid van getroffen systemen. Sommige kwetsbaarheden vereisen voorafgaande toegangsrechten, terwijl andere volledig op afstand en zonder authenticatie kunnen worden misbruikt.
De drie kwetsbaarheden die als kritiek zijn aangemerkt, CVE-2026-41635, CVE-2026-83355 en CVE-2026-2332, hebben een CVSS-score van 9,1 of hoger en bevinden zich in Agent Next Gen van Oracle Enterprise Manager Base Platform, Metrics van Oracle Enterprise Manager for Fusion Middleware en de Oracle Management Service (OMS) van Oracle Enterprise Manager Base Platform. Deze kwetsbaarheden kunnen volgens Oracle zonder authenticatie op afstand worden misbruikt, vereisen een lage aanvalscomplexiteit en geen gebruikersinteractie. Succesvolle exploitatie kan een hoge impact hebben op de vertrouwelijkheid en integriteit en,ook op de beschikbaarheid van getroffen systemen.
Het NCSC adviseert om de beveiligingsupdates voor de kritieke kwetsbaarheden met voorrang toe te passen.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0356Kwetsbaarheden verholpen in diverse SAP-productenEclipse Jetty's HTTP/1.1 parser improperly handles unclosed quoted strings in chunked transfer encoding extensions, enabling request smuggling attacks that can lead to security bypass, cache poisoning, and unauthorized access across multiple affected products.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenEclipse Jetty's HTTP/1.1 parser improperly handles unclosed quoted strings in chunked transfer encoding extensions, enabling request smuggling attacks that can bypass security controls and lead to cache poisoning, access control bypass, and session hijacking.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0311Kwetsbaarheden verholpen in Oracle Enterprise ManagerEclipse Jetty's HTTP/1.1 parser improperly handles unclosed quoted strings in chunked transfer encoding extensions, enabling request smuggling attacks that can lead to security bypass, cache poisoning, and unauthorized access.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0256Kwetsbaarheden verholpen in Oracle CommunicationsEclipse Jetty's HTTP/1.1 parser improperly handles chunked transfer encoding extensions with unclosed quoted strings, enabling request smuggling attacks that can lead to unauthorized access, cache poisoning, and security bypass.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0254Kwetsbaarheden verholpen in Oracle database productenEclipse Jetty's HTTP/1.1 parser improperly handles chunked transfer encoding extensions with unclosed quoted strings, enabling request smuggling attacks that can lead to unauthorized access, cache poisoning, and security bypass.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0169Kwetsbaarheden verholpen in Oracle Database ServerEclipse Jetty's HTTP/1.1 parser improperly handles unclosed quoted strings in chunked transfer encoding extensions, enabling request smuggling attacks that can lead to security bypass, cache poisoning, and unauthorized HTTP request injection.
Official advisory ↗