ThreatCluster

Multiple Remote Code Execution Vulnerabilities in Oracle Outside In Technology

First seen 9 Sep 2026, 22:43 UTC Zerodayinitiativewww.cve.org 61

Article Content

Browse articles
ThreatCluster

Oracle Outside In Technology has been found to have multiple vulnerabilities that allow remote attackers to execute arbitrary code. These vulnerabilities affect installations of the software and require user interaction, such as visiting a malicious page or opening a malicious file. The flaws include issues in parsing PostScript, GEM, WPS, and PDF files, leading to heap-based buffer overflows and integer overflows. Oracle has issued updates to address these vulnerabilities. The vulnerabilities are identified as ZDI-26-635, ZDI-26-636, ZDI-26-637, and ZDI-26-638. The vulnerabilities were reported to the vendor on 2026-04-08, and the advisories were publicly released on 2026-09-09. Security professionals are advised to apply the updates promptly to mitigate risks.

Key Points: • Four critical vulnerabilities in Oracle Outside In Technology allow remote code execution. • User interaction is required to exploit these vulnerabilities via malicious files or pages. • Oracle has released updates to address these vulnerabilities as of September 9, 2026.

Ask AI about this cluster

Timeline

2026-04-08
Vulnerabilities reported to Oracle
Multiple vulnerabilities in Oracle Outside In Technology were reported to the vendor for remediation.
Zerodayinitiative
2026-09-09
Public release of advisories
Oracle publicly released advisories for vulnerabilities ZDI-26-635 to ZDI-26-638, detailing the issues and patches.
Zerodayinitiative
2026-09-09
Advisories updated
The advisories for the vulnerabilities were updated to reflect the latest information and patches.
Zerodayinitiative