A critical vulnerability, CVE-2026-4408, has been published with a CVSS score of 9.0, affecting Samba file servers and classic domain controllers that use the "check password script" feature. The…
CVE-2026-46775 (CVSS 9.9) — Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acce
CVE. Sourced from nvd, summarised by Matproof.
AI Analysis
What changed and what to do.
A critical vulnerability has been published under CVE-2026-46775, affecting Oracle REST Data Services in versions 24.2.0 through 26.1.0. The flaw, rated 9.9 on the CVSS scale, is easily exploitable by a low-privileged attacker with network access, meaning it poses a severe risk of unauthorized data access or system compromise. The disclosure was made by the National Vulnerability Database on May 28, 2026, and falls under the Common Vulnerabilities and Exposures framework.
Organizations across all sectors that deploy Oracle REST Data Services are affected, particularly those in finance, healthcare, public administration, and any EU-regulated entity relying on Oracle databases for RESTful API integrations. Given the low privilege requirement and high severity, any organization using the affected versions should treat this as an urgent security incident, as it could lead to regulatory non-compliance under GDPR or sector-specific data protection rules if exploited.
Compliance teams should immediately verify whether their Oracle REST Data Services instances fall within the vulnerable version range and apply the vendor-supplied patch or upgrade to a non-affected version. Additionally, they should review access controls and monitor logs for signs of exploitation, and document remediation steps for potential regulatory audit inquiries. A risk assessment should be conducted to determine if any data breaches have occurred, with notification obligations under applicable EU regulations considered.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More CVE updates
Latest in CVE.
A critical vulnerability has been published under CVE-2026-24444, affecting SDMC NE6037 cable modem routers running firmware versions 7.1.6.0.25 and 7.1.6.1.9_B9. The issue involves a hardcoded…
A critical vulnerability has been published under CVE-2026-34311, affecting Oracle Hospitality OPERA 5 Property Services, specifically versions 5.6.19.24, 5.6.22, and 5.6.25.19. The vulnerability…
A critical vulnerability has been published under CVE-2026-46817, affecting the Oracle Payments component of Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. The flaw, rated 9.8…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.