Threat reportVulnerabilityTL-2026-1638

Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)

criticalACTIVE

Oracle Hospitality Simphony Vulnerabilities (TL-2026-1638) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-07-22. It has no confirmed attribution, affects Oracle Oracle Hospitality Simphony, references 4 CVEs (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169), maps to 19 MITRE ATT&CK techniques (T1005, T1046, T1059), and is covered by 9 detection rules and 18 indicators of compromise.

CVSS
9.1/10Critical
CVEs
4Referenced vulnerabilities
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-1638

Threat ID
TL-2026-1638
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
hospitality, food-service, retail, point-of-sale
Target regions
Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in Oracle Hospitality Simphony Vulnerabilities

Malware and tooling: NodeZero Rapid Response

How Oracle Hospitality Simphony Vulnerabilities works

Horizon3.ai researcher Jimi Sebree disclosed four unauthenticated, network-exploitable vulnerabilities in Oracle Hospitality Simphony POS (versions 19.8-19.8.5, 19.9-19.9.3, 19.10): a UNC path coercion flaw in the EGateway Printing Handler that discloses NTLM authentication material (CVE-2026-60167, CVSS 7.5), two arbitrary file write issues in the same component (CVE-2026-60168, CVSS 9.1 CRITICAL; CVE-2026-60169, CVSS 8.1), and an authentication bypass in the Simphony Kiosk application that grants access to the Kiosk administrator console and was demonstrated to enable arbitrary code execution (CVE-2026-60170, CVSS 7.5). Oracle shipped fixes in the July 2026 Critical Patch Update; Horizon3.ai simultaneously released a NodeZero Rapid Response module. Not present in CISA KEV; no active in-the-wild exploitation confirmed as of disclosure.

Oracle Hospitality Simphony is a widely deployed cloud-based point-of-sale (POS) platform used across the hospitality and food-service industry to process guest transactions, manage printing/kitchen-display workflows, and support self-service ordering via the Simphony Kiosk application. On 2026-07-21, Horizon3.ai attack researcher Jimi Sebree published technical analysis of four vulnerabilities affecting Simphony versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 (earlier, unsupported release lines may also be affected), coordinated with Oracle's July 2026 Critical Patch Update (cpujul2026), a mega-CPU that addressed 1,235 CVEs across 32 Oracle product families/1,449 patches in total.

CVE-2026-60167 is a UNC path coercion vulnerability in the EGateway Printing Handler. Because the handler insufficiently validates user-controlled input used to build printer/network paths, an unauthenticated network attacker can supply a crafted UNC path (e.g. pointing at an attacker-controlled SMB listener) and force the Simphony host to initiate an outbound SMB connection to it. Windows automatically attempts NTLM authentication during that outbound connection, disclosing the host's NTLM authentication material (NetNTLM hash) to the attacker. Horizon3.ai's write-up explicitly frames this as an SMB-relay-enabling primitive: the captured hash can be cracked offline to recover the plaintext service-account password, or relayed in real time (NTLM relay / SMB relay) against other hosts that accept the same credential, potentially yielding remote code execution or further lateral movement without ever needing the original password. CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — confidentiality-only impact reflecting the credential-disclosure primitive.

CVE-2026-60168 and CVE-2026-60169 are two related but independently tracked arbitrary file write vulnerabilities in the same EGateway Printing Handler, both stemming from insufficient validation of attacker-supplied paths/content before file operations are performed on the host filesystem. CVE-2026-60168 (CVSS 3.1 9.1 CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) is an easily exploitable (AC:L) unauthenticated HTTP-reachable flaw enabling unauthorized creation, deletion, or modification of critical data and denial of service (host crash). CVE-2026-60169 (CVSS 3.1 8.1 HIGH, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) is a harder-to-exploit (AC:H) variant of the same underlying weakness class but yields complete compromise of confidentiality, integrity, and availability when successful. Chained together, an attacker can write attacker-controlled files (e.g. a web shell or scheduled task payload) to the Simphony host, establishing persistence and staging code execution — Horizon3.ai's advisory groups both file-write CVEs under 'persistent code execution preparation' as the shared impact category.

CVE-2026-60170 is an authentication bypass in the Simphony Kiosk self-service ordering application (CVSS 3.1 7.5 HIGH, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Because the Kiosk application insufficiently validates a user-controlled input used in its authentication flow, an unauthenticated network attacker can bypass login and reach the Kiosk administrator console — a management interface not intended to be exposed to unauthenticated users. Horizon3.ai researchers demonstrated that administrator-console access can be leveraged to execute arbitrary code, establish persistence (including via unauthorized admin account creation, which Horizon3.ai flags as a specific post-exploitation indicator), access locally stored data (which may include payment/transaction artifacts depending on deployment), and pivot toward other assets on the same network segment as the kiosk terminal (common in retail/restaurant back-of-house LANs shared with POS controllers and payment infrastructure).

All four vulnerabilities are unauthenticated, network-exploitable (AV:N), require no user interaction (UI:N), require no privileges (PR:N), and were disclosed with coordinated Oracle patches in the July 2026 CPU. Horizon3.ai's public technical write-up withheld a full weaponized proof-of-concept but described attack mechanics in sufficient detail (UNC coercion pattern, file-write primitive, kiosk auth-bypass class, HTTP-endpoint reachability) that a motivated attacker could plausibly reconstruct working exploits, particularly given Simphony's prevalence in hospitality environments where POS/kiosk terminals are frequently internet- or vendor-network-adjacent. Horizon3.ai's mitigation guidance explicitly recommends Extended Protection for Authentication (EPA) alongside SMB signing, and monitoring for unauthorized SMB connections, unexpected file modifications, and unauthorized admin account creation. As of 2026-07-22 the four CVEs are not present in the CISA Known Exploited Vulnerabilities catalog (1,653 entries as of that date), consistent with the 'no active exploitation confirmed' assessment; Horizon3.ai released a single NodeZero Rapid Response test module allowing customers to both validate exploitability pre-patch and verify remediation post-patch without causing system damage.

MITRE ATT&CK techniques used in TL-2026-1638

Collection

T1005 Data from Local System

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Defense Evasion

T1070.004 File Deletion

Command and Control

T1071 Application Layer Protocol

Credential Access

T1110.002 Password Cracking; T1187 Forced Authentication; T1557.001 Name Resolution Poisoning and SMB Relay

Persistence

T1136.001 Local Account; T1505.003 Web Shell

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1485 Data Destruction; T1499 Endpoint Denial of Service

lateral-movement

T1550.002 Pass the Hash

Resource Development

T1587.001 Malware; T1588.005 Exploits

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Oracle Hospitality Simphony Vulnerabilities

  • Oracle — Oracle Hospitality Simphony
    Vulnerable versions: 19.8; 19.8.1; 19.8.2; 19.8.3; 19.8.4; 19.8.5; 19.9; 19.9.1; 19.9.2; 19.9.3
    Fixed in: Patched via Oracle Critical Patch Update - July 2026 (cpujul2026)

Remediation for Oracle Hospitality Simphony Vulnerabilities

Patches

  • Oracle Critical Patch Update - July 2026 (cpujul2026)

Immediate actions

  • Apply Oracle's July 2026 Critical Patch Update to all Oracle Hospitality Simphony deployments running 19.8-19.8.5, 19.9-19.9.3, or 19.10
  • Restrict network access to the EGateway Printing Handler and Kiosk administrator console to trusted management networks only
  • Enforce SMB signing and Extended Protection for Authentication (EPA); block outbound SMB (TCP 445, 137-139) from Simphony hosts to the internet to prevent NTLM hash disclosure via coerced authentication
  • Disable or restrict NTLM authentication in favor of Kerberos where operationally feasible on Simphony hosts

Workarounds

  • If immediate patching is not possible, block inbound access to the EGateway Printing Handler and Kiosk admin console from untrusted networks
  • Enable SMB signing enforcement to mitigate NTLM relay even if hash disclosure occurs
  • Monitor for unexpected outbound SMB connection attempts and unauthorized admin account creation originating from Simphony hosts

Longer-term hardening

  • Segment POS/kiosk terminals onto isolated VLANs separate from payment processing and corporate infrastructure
  • Deploy EDR/host monitoring on Simphony EGateway and Kiosk hosts to detect anomalous outbound SMB connections, unexpected file writes, and unauthorized admin account creation
  • Rotate credentials for any service accounts used by the EGateway Printing Handler following patch deployment
  • Implement egress filtering to block unsolicited outbound SMB from POS network segments
  • Run Horizon3.ai NodeZero Rapid Response (or equivalent authorized testing) post-patch to verify remediation effectiveness

CVEs associated with Oracle Hospitality Simphony Vulnerabilities

CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170

Weaknesses (CWE) in Oracle Hospitality Simphony Vulnerabilities

CWE-434, CWE-287, CWE-20, CWE-73

Timeline of Oracle Hospitality Simphony Vulnerabilities

  • NVD published individual CVE records for CVE-2026-60167 through CVE-2026-60170, each referencing Oracle's cpujul2026 advisory as the sole reference source.
  • Horizon3.ai's advisory recommended interim mitigations including SMB signing enforcement, Extended Protection for Authentication (EPA), network segmentation, blocking direct internet exposure of admin interfaces, and monitoring for suspicious outbound SMB connections, unexpected file modifications, and unauthorized admin account creation on Simphony hosts.
  • Horizon3.ai released a single NodeZero Rapid Response test module enabling customers to check exploitability of the disclosed Simphony vulnerabilities pre-patch and verify remediation post-patch without causing system damage.
  • Oracle published CVSS 3.1 base scores for the four CVEs: 7.5 (CVE-2026-60167), 9.1 CRITICAL (CVE-2026-60168), 8.1 (CVE-2026-60169), and 7.5 (CVE-2026-60170), all AV:N/AC:L-or-H/PR:N/UI:N.
  • Oracle released fixes for all four Simphony vulnerabilities as part of the July 2026 Critical Patch Update (cpujul2026), a mega-CPU addressing 1,235 CVEs across 32 product families / 1,449 patches total.
  • Horizon3.ai researcher Jimi Sebree publicly disclosed technical details of CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, and CVE-2026-60170 affecting Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, and 19.10.
  • Report ingested into TL-Intel-Harness RSS backlog from the Horizon3.ai Attack Research feed for hunt/research triage.
  • Verification against the CISA Known Exploited Vulnerabilities catalog (1,653 entries as of 2026-07-22) confirmed none of the four Simphony CVEs are listed, corroborating the 'no active exploitation confirmed' assessment at time of research.

Sources cited for Oracle Hospitality Simphony Vulnerabilities

Detection coverage for TL-2026-1638

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1638 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats