Summary
- The Dutch NCSC has warned of severe Oracle Fusion Middleware vulnerabilities with maximum CVSS scores of 10.0.
- Affected products include Oracle Data Integrator, Oracle Coherence, and Oracle WebLogic Server.
- Middleware exposure can affect business processes because these platforms connect applications, data, and systems.
The Netherlands’ National Cyber Security Centre has urged organisations to update Oracle Fusion Middleware immediately after warning that several severe vulnerabilities can be exploited over the network without credentials.
The 22 July alert identifies affected products including Oracle Data Integrator, Oracle Coherence, and Oracle WebLogic Server. The vulnerabilities include CVE-2026-47056 and CVE-2026-60217, with a maximum CVSS score of 10.0. The Dutch agency rates both the likelihood of exploitation and the potential damage as high.
Oracle Fusion Middleware is used to connect applications and systems, exchange data, and support business processes. That role gives the alert a wider operational dimension than a single-server vulnerability. Middleware can sit between databases, enterprise applications, customer systems, identity services, reporting tools, and integration layers.
The Dutch NCSC says exploitation could allow an attacker to run malicious code, view sensitive data, or take over a system, depending on the vulnerability. It also warns that attackers may be able to view, change, delete, or lose data, while business processes may fail. Those outcomes are material for organisations that depend on middleware to move information between core systems.
The ownership problem is often the hardest part of middleware response. Business units may depend on the processes it supports without knowing the product versions underneath. Infrastructure teams may operate the server but not own the application logic. Suppliers, managed service providers, and implementation partners may hold administrative responsibility. The Dutch NCSC’s advice to contact IT service providers where organisations are unsure whether they use affected versions reflects that complexity.
European cyber regulation is increasingly intolerant of that kind of uncertainty. NIS2 and national implementing laws expect essential and important entities to understand dependencies, manage vulnerabilities, and supervise suppliers. Middleware vulnerabilities expose whether those governance processes work in practice, particularly when a high-severity advisory requires rapid coordination across technical and commercial boundaries.
The response should start with identification. Organisations need to confirm whether Oracle Fusion Middleware is present, which components are deployed, whether instances are exposed to untrusted networks, who administers them, and which business processes rely on them. Patching should be followed by log review, service account checks, network access review, and confirmation from relevant suppliers that updates have been applied.
Business continuity planning also belongs in the response. Emergency updates to integration platforms can affect dependent applications, so resilience depends on tested change processes, maintenance windows, backups, rollback plans, and clear communication between application owners and infrastructure teams.
The Dutch warning is brief, but the exposure it describes is substantial. Middleware often works out of sight, carrying data between systems and services. When that layer carries unauthenticated critical vulnerabilities, the risk is not limited to the affected product. It reaches the business processes that product connects.



