CVE-2026-47040Disclosure(oracle / database_server)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch oracle database_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Net Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • database_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
database_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-31: 1PoC Mentioned / Linked · 2026-07-31: 1Patch / Workaround · 2026-07-31: 107-31
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CCB Alert@CCBalert
    Disclosure

    Warning: Multiple (100+) vulnerabilities in #Oracle #WebLogic Server Fusion Middleware. #CVE-2026-60206 #CVE-2026-61211 #CVE-2026-47040 #CVE-2026-4738. There are publicly available proof-of-concepts #PoC See advisory https://www.oracle.com/security-alerts/cpujul2026.html #Patch #Patch #Patch

    Post summary

    The tweet warns about a large set of newly disclosed Oracle WebLogic vulnerabilities, notes publicly available proof‑of‑concepts, and points to an official advisory containing patch information.

    00011390
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacledatabase_server---

Explore more