Deserialization flaw in Oracle Outside In PDF Export SDK 8.5.8
CVE-2026-60392 is a vulnerability in the Outside In PDF Export SDK component of Oracle Outside In Technology 8.5.8, which Oracle has tagged as deserialization of untrusted data (CWE-502); ZDI's advisory additionally characterizes it as an integer overflow while parsing PDF files that can lead to remote code execution. An unauthenticated attacker who has obtained logon access to the infrastructure where Outside In Technology runs must get a person other than themselves to interact with the system (user interaction required per the CVSS vector) for the local (AV:L) attack to succeed. A successful attack results in takeover of Outside In Technology with high confidentiality, integrity, and availability impact, reflected in the CVSS 3.1 base score of 7.8. Affected organizations are those running the 8.5.8 release of the PDF Export SDK, which Oracle ships within Fusion Middleware and licenses to third-party document-processing products. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
· Oracle Outside In Technology (Outside In PDF Export SDK, Oracle Fusion Middleware) 8.5.8—
Memory Corruption in WPS File Parsing in Oracle Outside In Technology 8.5.8
Oracle Outside In Technology (Outside In Core) version 8.5.8 contains a memory corruption flaw triggered while parsing WPS-format documents, per the Zero Day Initiative advisory. An unauthenticated attacker who has logon access to the infrastructure where the Outside In engine runs must get a person other than themselves to interact with the crafted file, at which point the parsing process is compromised. Successful exploitation results in takeover of Oracle Outside In Technology, with high confidentiality, integrity, and availability impact (CVSS 3.1 score 7.8, local attack vector with user interaction). Because Outside In is a document-conversion/preview engine embedded inside Oracle Fusion Middleware and other products, anyone running an affected deployment that processes untrusted WPS documents is exposed. There is currently no public proof of concept, no listing in CISA's KEV, and a low 0.2% EPSS probability of exploitation within 30 days, indicating no known exploitation activity.
· Oracle Outside In Technology (Outside In Core component), part of Oracle Fusion Middleware 8.5.8niche
Oracle Outside In Technology GEM File Parsing Integer Overflow Allows Takeover
CVE-2026-60413 is a vulnerability in the Outside In Core component of Oracle Outside In Technology 8.5.8, Oracle's document parsing and conversion engine that is bundled within Oracle Fusion Middleware. An unauthenticated attacker who can log on to the infrastructure where Outside In Technology executes (CVSS attack vector AV:L, no privileges required) can trigger the flaw, and successful attacks require interaction from a user other than the attacker — consistent with a crafted file being submitted for parsing. The related ZDI advisory (ZDI-26-637) characterizes the issue as an integer overflow when parsing GEM files that can lead to remote code execution, while Oracle's entry maps the weakness to CWE-200 and rates it 7.8 (high) with high confidentiality, integrity, and availability impacts, resulting in takeover of Outside In Technology. Any deployment running the affected 8.5.8 release of Outside In Technology — typically embedded inside Oracle Fusion Middleware or other products that use the engine for document conversion — is affected. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is known.
· Oracle Outside In Technology (Outside In Core, product of Oracle Fusion Middleware) 8.5.8 (supported version listed as affected)—
PostScript Parsing Heap Overflow in Oracle Outside In Technology 8.5.8
CVE-2026-60412 is a flaw in the Outside In Core component of Oracle Outside In Technology 8.5.8, a document-parsing engine distributed as part of Oracle Fusion Middleware; the CVE is classified as CWE-502 (deserialization of untrusted data), while the related ZDI advisory (ZDI-26-636) describes it as a heap-based buffer overflow triggered when parsing PostScript files. The attack vector is local (AV:L): an unauthenticated attacker must have logon to the infrastructure where Outside In executes, and successful exploitation additionally requires human interaction from someone other than the attacker, typically a user or service processing an attacker-supplied file. A successful attack can result in takeover of the Outside In Technology instance with high confidentiality, integrity and availability impact (CVSS 3.1 7.8), and the ZDI advisory characterizes the outcome as remote code execution. The affected version in Oracle's advisory is 8.5.8, so organizations running this release directly or bundled inside Oracle Fusion Middleware products are in scope. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (22nd percentile).
· Oracle Outside In Technology (Outside In Core, Oracle Fusion Middleware) 8.5.8large