Junglewise Threat Intelligence

CVE-2026-61225: Oracle Communications Converged Application Server takeover in Core component

CVE-2026-61225 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Converged Application Server. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Communications Converged Application Server, a platform used by telecommunications providers to deliver multimedia services. An unauthenticated attacker could remotely exploit this flaw to gain full control over the server. A successful attack could lead to a complete service outage, unauthorized access to sensitive communication data, and total compromise of the application environment.

Technical details

A vulnerability in the Core component of Oracle Communications Converged Application Server (versions 8.2 and 8.3) allows for a complete system takeover. The flaw is exploitable by an unauthenticated attacker via the network using TCP/IP. While the attack complexity is rated as high—suggesting specific timing or environmental conditions are required—a successful exploit results in a total loss of confidentiality, integrity, and availability. Oracle addressed this issue in the July 2026 Critical Patch Update.

Affected products

  • Oracle Communications Converged Application Server 8.2, 8.3

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats