Skip to content
ThreatCluster

Critical Vulnerabilities in Oracle MySQL and Identity Manager Exposed

First seen 27 Sep 2026, 11:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •CVE-2026-46870 affects Oracle MySQL Shell, allowing compromise by low-privileged attackers.
  • •CVE-2026-83340 targets Oracle Identity Manager, with similar exploitation potential.
  • •Both vulnerabilities have high CVSS scores, indicating severe risks to affected systems.

Two significant vulnerabilities have been identified in Oracle products, CVE-2026-46870 and CVE-2026-83340. CVE-2026-46870 affects the MySQL Shell (version 2026.2.0+9.6.1), allowing low-privileged attackers with network access to compromise the shell, with a CVSS score of 8.5. CVE-2026-83340 impacts Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0), enabling similar exploitation via HTTP, rated at a CVSS score of 8.8. Both vulnerabilities could lead to a complete takeover of the affected systems. The NCSC has developed a machine-learning driven score to assess the relevance of these vulnerabilities for Dutch organizations, which is automatically updated with new information. Organizations using these Oracle products are advised to apply patches immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-26
CVE-2026-46870 disclosed
Vulnerability in Oracle MySQL Shell allows low-privileged attackers to compromise the shell, CVSS score 8.5.
Vulnerabilities.Ncsc.Nl
2026-09-26
CVE-2026-83340 disclosed
Vulnerability in Oracle Identity Manager allows HTTP-based attacks, CVSS score 8.8.
Vulnerabilities.Ncsc.Nl

More articles in this cluster (8)