ZeroHour
Story · 1 source · 4 articlesfirst updated ()

ZDI publishes four Oracle Outside In Technology file-parsing RCE advisories (CVSS 7.8) requiring user interaction

What's new: First merged summary for this story: on 2026-09-09, ZDI simultaneously disclosed four new CVEs in Oracle Outside In Technology file parsers (PDF, PostScript, GEM, and WPS), all CVSS 7.8 user-triggered remote code execution flaws with no reported exploitation.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-09, the Zero Day Initiative disclosed four CVSS 7.8 remote code execution flaws in Oracle Outside In Technology file parsing — PDF (CVE-2026-60392), PostScript (CVE-2026-60412), GEM (CVE-2026-60413), and WPS (CVE-2026-60414) — all requiring a user…

The Zero Day Initiative published four advisories on 2026-09-09 covering remote code execution vulnerabilities in file parsing within Oracle Outside In Technology, each rated CVSS 7.8. ZDI-26-635 (CVE-2026-60392) is an integer overflow in PDF file parsing; ZDI-26-636 (CVE-2026-60412) is a heap-based buffer overflow in PostScript file parsing; ZDI-26-637 (CVE-2026-60413) is an integer overflow in GEM file parsing; and ZDI-26-638 (CVE-2026-60414) is a memory corruption flaw in WPS file parsing. In every case, successful exploitation allows remote attackers to execute arbitrary code on affected installations, but only after user interaction — the target must open a malicious file or visit a malicious page. The advisories report no in-the-wild exploitation (stated explicitly for ZDI-26-636, ZDI-26-637, and ZDI-26-638; the ZDI-26-635 report does not state an exploitation status). No disagreement on ratings, attack requirements, or affected product exists across the four reports.

  • Four ZDI advisories published 2026-09-09 against Oracle Outside In Technology: ZDI-26-635, ZDI-26-636, ZDI-26-637, ZDI-26-638.
  • ZDI-26-635 / CVE-2026-60392: integer overflow in PDF file parsing.
  • ZDI-26-636 / CVE-2026-60412: heap-based buffer overflow in PostScript file parsing.
  • ZDI-26-637 / CVE-2026-60413: integer overflow in GEM file parsing.
  • ZDI-26-638 / CVE-2026-60414: memory corruption in WPS file parsing.
  • All four vulnerabilities are rated CVSS 7.8 and permit remote code execution on affected installations.
  • All four require user interaction: opening a malicious file or visiting a malicious page.
  • No in-the-wild exploitation is reported in the advisories (explicitly stated for three of the four; not addressed in the ZDI-26-635 report).

Coverage timeline

  1. · 6d ago
    ZDI Published Advisories· 22
    ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    ZDI disclosed a heap-based buffer overflow in Oracle Outside In Technology's PostScript parsing (CVE-2026-60412) enabling user-triggered remote code execution.

  2. · 6d ago
    ZDI Published Advisories· 22
    ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability

    ZDI disclosed an integer overflow in Oracle Outside In Technology's GEM file parsing (CVE-2026-60413) enabling user-triggered remote code execution.

  3. · 6d ago
    ZDI Published Advisories· 22
    ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

    ZDI disclosed memory corruption in Oracle Outside In Technology's WPS file parsing (CVE-2026-60414) enabling user-triggered remote code execution.

  4. · 6d ago
    ZDI Published Advisories· 25
    ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

    ZDI disclosed CVE-2026-60392, an integer overflow in Oracle Outside In PDF parsing enabling remote code execution, rated CVSS 7.8.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60392
+3 in the same advisory: …60412 …60413 …60414
Deserialization flaw in Oracle Outside In PDF Export SDK 8.5.8

CVE-2026-60392 is a vulnerability in the Outside In PDF Export SDK component of Oracle Outside In Technology 8.5.8, which Oracle has tagged as deserialization of untrusted data (CWE-502); ZDI's advisory additionally characterizes it as an integer overflow while parsing PDF files that can lead to remote code execution. An unauthenticated attacker who has obtained logon access to the infrastructure where Outside In Technology runs must get a person other than themselves to interact with the system (user interaction required per the CVSS vector) for the local (AV:L) attack to succeed. A successful attack results in takeover of Outside In Technology with high confidentiality, integrity, and availability impact, reflected in the CVSS 3.1 base score of 7.8. Affected organizations are those running the 8.5.8 release of the PDF Export SDK, which Oracle ships within Fusion Middleware and licenses to third-party document-processing products. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

Do: Apply the fix for CVE-2026-60392 released in the corresponding Oracle Critical Patch Update; Oracle lists only version 8.5.8 of the PDF Export SDK as affected, so consult the CPU advisory for the fixed release and upgrade accordingly. Inventory which Fusion Middleware components and OEMed products embed Outside In on your hosts and restrict local logon to those systems to limit the attacker's ability to stage the required user interaction. Given the low EPSS (0.3%), absence of a public PoC, and user-assisted local vector, patch at your normal maintenance cadence rather than treating it as an emergency.

7.8<1%
  • Oracle Outside In Technology (Outside In PDF Export SDK, Oracle Fusion Middleware) 8.5.8