CVE-2026-21452 – Oracle

CVSS 7.5 IMPORTANT Critical - Same Day Deployment

“One update can close hundreds of attack paths when it reaches every critical component.”

This security release addresses vulnerabilities across a broad range of open-source and commercial software components used throughout enterprise environments. The update includes multiple Critical, High, Medium, and Low severity vulnerabilities affecting web frameworks, databases, messaging platforms, networking libraries, cryptographic libraries, virtualization software, operating system components, logging frameworks, and developer tools. The fixes improve memory safety, input validation, authentication, authorization, bounds checking, cryptographic handling, and resource management while reducing the overall attack surface.

The release includes several Critical vulnerabilities with confirmed CVSS scores of 9.8, 9.4, and 9.1, together with numerous High severity vulnerabilities ranging from 7.0 to 8.9. Several entries include verified public proof-of-concept availability, while no active exploitation is identified in the provided data.

CVE LIST:

CVE-2024-28168 CVE-2024-29371 CVE-2024-37997 CVE-2024-47554 CVE-2024-7254 CVE-2025-13465 CVE-2025-27821 CVE-2025-48924 CVE-2025-5115 CVE-2025-54920 CVE-2025-67030 CVE-2025-67721 CVE-2025-67735 CVE-2025-68161 CVE-2025-7962 CVE-2025-8916 CVE-2026-1002 CVE-2026-10879 CVE-2026-1225 CVE-2026-21452 CVE-2026-22029 CVE-2026-2332 CVE-2026-23865 CVE-2026-24281 CVE-2026-25526 CVE-2026-25639 CVE-2026-27727 CVE-2026-28387 CVE-2026-33557 CVE-2026-33871 CVE-2026-34478 CVE-2026-34481 CVE-2026-35554 CVE-2026-41044 CVE-2026-4176 CVE-2026-43512 CVE-2026-46975 CVE-2026-47022 CVE-2026-47038 CVE-2026-47039 CVE-2026-47040 CVE-2026-47045 CVE-2026-47046 CVE-2026-47060 CVE-2026-47061 CVE-2026-4738 CVE-2026-54285 CVE-2026-54513 CVE-2026-54515 CVE-2026-54518 CVE-2026-60156 CVE-2026-60157 CVE-2026-60172 CVE-2026-60175 CVE-2026-60394 CVE-2026-60395 CVE-2026-60396 CVE-2026-60397 CVE-2026-60398 CVE-2026-60399 CVE-2026-60400 CVE-2026-60630 CVE-2026-61211 CVE-2026-7210 CVE-2026-7383

Vulnerability Coverage by Product / Subsystem

Operating Systems

Linux Kernel

Oracle Database Server

Oracle Net Services

GoldenGate Stream Analytics

Application Servers & Web Platforms

Apache Tomcat

Apache ActiveMQ

Apache Kafka

Apache Kafka Clients

Apache Spark

Eclipse Jetty

React Router

Apache ZooKeeper

Databases

Oracle Database Server

MongoDB Server

Networking & Communication

Netty

OpenSSL

Apache Hadoop HDFS Native Client

msgpack-java

Eclipse Vert.x

Jakarta Mail

axios

Logging & Monitoring

Apache Log4j Core

Apache Log4j JSON Template Layout

OpenTelemetry JavaScript

Serialization / Data Processing

Protocol Buffers

Jackson Databind

MessagePack Java

Apache XML Graphics FOP

Apache Commons IO

Apache Commons Lang

JinJava

Cryptography & Security Libraries

BC Java

OpenSSL

Logback-core

jose4j

mchange-commons-java

JavaScript / Web Libraries

Lodash

axios

React Router

Developer & Build Tools

Plexus Utils

Aircompressor

GDAL

Perl

FreeType

Messaging & Middleware

Apache Kafka

Apache ActiveMQ

Netty

Visualization & Engineering Software

Siemens JT Open

JT2Go

PLM XML SDK

Teamcenter Visualization

Key Security Themes

Remote code execution prevention

Authentication and authorization hardening

Memory corruption mitigation

Use-after-free and buffer overflow fixes

Bounds validation improvements

Deserialization security

XML and request parsing protections

Denial-of-service resilience

Information disclosure prevention

Race condition and concurrency fixes

Multiple Critical vulnerabilities were addressed across widely deployed enterprise software.

Memory safety, authentication, deserialization, and input validation represent the primary security improvements.

Several vulnerabilities have publicly available proof-of-concept code, increasing the urgency of patch deployment.

Applying these updates significantly reduces risk across enterprise application stacks and infrastructure.

Key Details

Affected Product
Msgpack Messagepack
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-400
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.