Visualização de leitura

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-21962 is a critical, unauthenticated vulnerability affecting the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.

An attacker does not need an account or valid credentials. With network access, they can exploit the flaw remotely through HTTP and potentially compromise the affected server. Successful exploitation could allow the attacker to access, modify or delete critical data, potentially gaining broad access to information available through the affected components.

“Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data,” CISA reports.

The vulnerability also has a scope-change impact, meaning an attacker who exploits it could potentially affect other systems or applications connected to the vulnerable Oracle components.

The flaw affects versions: 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0.

In practical terms, this is dangerous because an internet-accessible Oracle WebLogic proxy component could provide an attacker with a path into critical backend systems without requiring authentication.

In March 2026, CloudSEK researchers detected attacks targeting several known flaws in Oracle WebLogic against its honeypot network. Attackers also targeted CVE-2026-21962 along with older WebLogic RCE vulnerabilities, including CVE-2020-14882/14883, CVE-2020-2551 and CVE-2017-10271.

“This report analyzes attack data collected from a high-interaction honeypot simulating a vulnerable Oracle WebLogic Server (v14.1.1.0.0) over a 12-day period (Jan 22 – Feb 3, 2026). The primary focus is the immediate and widespread exploitation of the newly disclosed, critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2026-21962 (CVSS: 10.0).” ” reads the report published CloudSEK.

“In addition to CVE-2026-21962, the honeypot captured attacks targeting other persistent, critical WebLogic RCE flaws, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE). This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaw by August 27, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability

Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update, addressing flaws across its enterprise software portfolio.

The release includes several critical Oracle WebLogic Server vulnerabilities that could allow an unauthenticated remote attacker to take complete control of affected servers.

The update, published on August 18, covers Oracle Database, Fusion Middleware, E-Business Suite, Java SE, MySQL, Enterprise Manager, PeopleSoft, Communications products, and many other platforms.

Oracle strongly urged customers to apply the updates without delay, noting that attackers have previously exploited known flaws when organizations failed to patch them.

Oracle Releases 943 Security Patches

The most urgent fixes affect Oracle WebLogic Server, a widely deployed application server used by large organizations to host business-critical applications. Oracle fixed multiple remotely exploitable flaws with a CVSS severity score of 9.8 out of 10.

The affected flaws include CVE-2026-60698, CVE-2026-60672, and CVE-2026-60696, which impact the WebLogic Server Core component through the IIOP and T3 protocols.

These vulnerabilities are particularly dangerous because they can be exploited remotely without authentication and can affect confidentiality, integrity, and availability.

In practical terms, a successful attacker may be able to execute unauthorized actions, steal sensitive data, change application content, disrupt business services, or potentially gain full control of a vulnerable WebLogic environment.

Critical WebLogic vulnerabilities

CVEAffected ComponentProtocolCVSS 3.1
CVE-2026-60698WebLogic Server CoreIIOP9.8
CVE-2026-60672WebLogic Server CoreT3, IIOP9.8
CVE-2026-60696WebLogic Server CoreT3, IIOP9.8
CVE-2026-60977WebLogic Server WLS Core ComponentsRMI9.8
CVE-2026-60702WebLogic Server CoreT3, IIOP9.9

CVE-2026-60698 affects WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. CVE-2026-60672 and CVE-2026-60696 affect the same versions.

Oracle also patched CVE-2026-60977, a critical RMI-related flaw affecting WebLogic Server releases 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Each of these issues received a CVSS score of 9.8.

Another high-severity WebLogic issue, CVE-2026-60702, has a CVSS score of 9.9. It affects the WebLogic Core component and uses T3 or IIOP as the attack vector. Unlike the 9.8-rated flaws, this vulnerability requires a low-privileged authenticated user.

However, successful exploitation could still have a broad impact across the affected system, including a high level of compromise of data confidentiality, integrity, and availability.

Overall, Oracle Fusion Middleware received 262 new security patches, with 182 vulnerabilities identified as remotely exploitable without authentication.

This makes Fusion Middleware one of the most significant product groups in the August update. The advisory also includes a maximum-severity CVSS 10.0 flaw, CVE-2026-61241, in Oracle Internet Directory’s LDAP Server component.

Oracle also addressed serious vulnerabilities in other products. Oracle Commerce received 66 patches, including several remotely exploitable vulnerabilities with a CVSS score of 9.8.

Oracle E-Business Suite received 120 patches, while Oracle Database Products received 17 security fixes. Several high-impact issues were also patched in Oracle Essbase, Enterprise Manager, Financial Services applications, and Oracle Hospitality Simphony.

Organizations should prioritize internet-facing WebLogic servers, especially systems with T3, IIOP, or RMI services exposed to untrusted networks.

Security teams should identify affected versions, obtain the relevant patches through Oracle’s Patch Availability Documents, test updates in non-production environments, and deploy them as quickly as operationally possible.

Where immediate patching is not possible, administrators should restrict access to exposed protocols and limit unnecessary network reachability. However, Oracle cautions that such workarounds do not fix the underlying vulnerabilities.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability appeared first on Cyber Security News.

Oracle Releases 943 Security Patches to Fix Critical Vulnerabilities Across Enterprise Products

Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities across its enterprise software portfolio. This update affects Oracle products under both Premier Support and Extended Support. It includes fixes for flaws tracked by various CVE identifiers. Oracle Releases 943 Security Patches The vulnerabilities […]

The post Oracle Releases 943 Security Patches to Fix Critical Vulnerabilities Across Enterprise Products appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?

A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform.

On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the system could independently offer retention incentives to unhappy accounts without a human ever touching a keyboard.

Then I asked a simple question: “What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?”

The room went completely silent. The VP looked at the director of IT, the director of IT looked at the chief risk officer, and everyone realized the same thing at the exact same moment. They had spent three months evaluating software licenses and security protocols, but nobody had asked who gave the software permission to sign off on corporate spending.

Major software providers like Salesforce, SAP and Oracle are rapidly moving beyond simple report writers and conversational chatbots. They are embedding active, autonomous agents directly into the transactional core of systems that manage your revenue, customer agreements and financial ledgers. According to Gartner’s latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These applications do not just summarize data: they issue refunds, alter contract terms and trigger supply chain orders.

When I review these deployments with client teams, the core problem has nothing to do with artificial intelligence. It is a fundamental breakdown in corporate delegation and signing authority.

The breakdown of the corporate signing matrix

Every mature company I work with operates on a clear delegation of authority matrix. This framework dictates exactly who can sign off on financial commitments. A vice president might have authorization to approve spending up to $500,000, a director might sit at $100,000 and a front-line manager might be capped at $500. For two decades, technology leaders have spent millions of dollars building security and compliance controls to ensure every human employee operates strictly within those limits.

Yet when a software vendor releases an update featuring autonomous agents, companies routinely grant these features unrestricted operational freedom. Because the capability arrives as a native feature inside an existing application, business units enable it with a single click. In my advisory work, I repeatedly see organizations grant third-party software features more financial freedom than their own human managers.

This represents a massive blind spot in executive governance. McKinsey’s global surveys on artificial intelligence reveal a striking pattern across the enterprise landscape: while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The quiet cost of shadow delegation

In my audits, this rarely manifests as a dramatic system crash. It plays out as a quiet margin leak. In one organization I reviewed, a department head had enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket, and to prevent the account from churning, it independently applied an unapproved 15 percent discount to their multi-year contract.

The customer was happy, and the account manager considered the client saved. But from an executive perspective, an unvetted third-party algorithm just executed an unauthorized contract modification that eroded company margins. When the finance team conducted a quarterly audit, they did not discover an employee violating spending policy. They discovered a black-box automated decision that bypassed every internal approval control in the company.

When an auditor tests your internal controls, presenting a log showing that a vendor’s algorithm made an unauthorized financial change does not satisfy the requirement. If an action requires managerial sign-off when performed by a human being, letting software execute it independently is a major control failure.

How I advise executive teams to handle automated authority

Protecting your organization does not mean turning off these tools or falling behind on technology. It means treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check.

Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management. Zero-trust simply means that no user, device or automated tool gets implicit trust. Every proposed action must be validated against explicit business rules before it happens.

When I help enterprise teams design these safeguards, we establish a practical three-tiered boundary for automated tools:

  • Read and draft permission: Automated tools can freely analyze trends, draft emails and assemble internal reports. No human sign-off is needed to create a draft, but the system cannot publish or execute anything on its own.
  • Standard administrative permission: Tools can handle routine administrative tasks or process standard requests below a strict financial cap (such as a $50 service credit), provided every single action is logged in an audit file that managers review weekly.
  • Restricted financial permission: Any action that alters contract terms, changes pricing tiers or issues major refunds are strictly held in an authorization queue. The system generates the request, but a human manager must click “approve” before the change hits the live database.

As a technology executive, you cannot control what automated features software providers bundle into their platforms. You can, however, control the financial boundaries and signing authority those tools are permitted to exercise within your business.

What to do at your next executive leadership meeting

  1. Ask for an automated authority inventory: Have your team audit your core software platforms to identify every automated feature currently running with permission to alter financial or customer records.
  2. Revert to draft-only mode: Instruct your team to default all vendor-supplied automated agents to “draft only” until a clear business case justifies giving them independent operational authority.
  3. Establish a firm human-in-the-loop rule: Require a strict organizational policy that no automated system can modify pricing, contracts or financial ledgers without explicit manager approval.

Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products

July 2026 Critical Patch Update

Oracle has released its July 2026 Critical Patch Update, delivering one of its largest quarterly security releases to date. The latest Oracle security patch addresses more than 1,400 vulnerabilities across hundreds of products, with the company indicating that artificial intelligence likely played a significant role in identifying most of the flaws.  According to Oracle, the July 2026 Critical Patch Update contains 1,449 security patches, covering 1,434 unique Common Vulnerabilities and Exposures (CVEs) across 334 products.  

July 2026 Critical Patch Update Covers Hundreds of Oracle Products 

The latest Oracle security patch spans a wide range of enterprise products and platforms. Among the affected products are Database Server, Oracle APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.  The July 2026 Critical Patch Update also includes security fixes for Enterprise Manager, Financial Services Applications, Food and Beverage Applications, Fusion Middleware, Analytics, HealthCare Applications, Hospitality Applications, Java SE, JD Edwards, MySQL, PeopleSoft, Retail Applications, Siebel CRM, Supply Chain, Systems, Utilities Applications, and Virtualization.  By addressing vulnerabilities across such an extensive product lineup, the Oracle security patch aims to reduce the risk posed by security weaknesses that could affect organizations running Oracle technologies in production environments. 

Hundreds of Vulnerabilities Can Be Exploited Remotely 

A notable aspect of the July 2026 Critical Patch Update is the number of flaws that attackers could potentially exploit without requiring authentication. Oracle stated that roughly 600 of the patches fix vulnerabilities that can be exploited remotely by unauthenticated attackers. In addition, hundreds of the addressed security flaws have been assigned critical severity ratings, emphasizing the importance of applying the latest Oracle security patch without delay. Among Oracle's products, the highest number of vulnerabilities were addressed in: 
  • E-Business Suite: 410 vulnerabilities 
  • Fusion Middleware: 355 vulnerabilities 
  • Communications: 168 vulnerabilities 
  • PeopleSoft: 84 vulnerabilities 
These figures highlight that some of Oracle's most widely deployed enterprise applications received a significant share of the security fixes included in the quarterly update.

AI-Driven Vulnerability Discovery Appears to Have Played a Major Role 

One of the most notable aspects of the July 2026 Critical Patch Update is Oracle's growing use of artificial intelligence for security research. Only a few dozen of the vulnerabilities included in the release were credited to external security researchers. This indicates that the overwhelming majority of the discovered flaws were identified internally, likely with the assistance of AI-driven vulnerability analysis. Earlier this year, Oracle disclosed that it has access to leading artificial intelligence systems, including Anthropic's Claude Mythos and OpenAI's most capable models. According to the company, these AI technologies are being used to accelerate vulnerability discovery and improve the speed and accuracy of security patch development.  Oracle also said it is applying this AI-driven vulnerability approach across its own software and cloud services, Oracle Health offerings, and the open source components that it both develops and depends on.

Organizations Urged to Apply the Oracle Security Patch Promptly 

The release of the July 2026 Critical Patch Update comes amid continued efforts by threat actors to exploit vulnerabilities in enterprise software before organizations can deploy security updates.  Oracle product vulnerabilities have previously been targeted in real-world attacks. The company cited examples that include the exploitation of a PeopleSoft zero-day vulnerability as well as a recently patched Oracle E-Business Suite (EBS) vulnerability. Given the number of remotely exploitable and high-severity issues resolved in the Oracle security patch, organizations using affected Oracle products are advised to install the updates as soon as possible. Prompt deployment can help reduce exposure to attacks that take advantage of publicly known vulnerabilities before systems are secured. With 1,449 security patches addressing 1,434 unique CVEs across 334 products, the July 2026 Critical Patch Update represents one of Oracle's most extensive quarterly security releases.  

U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog.

The flaws added to the catalog are:

  • CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
  • CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability  

The vulnerability CVE-2023-4346 (CVSS score of 7.5) is an improper account lockout mechanism flaw affecting KNX devices that use KNX Connection Authorization Option 1. An attacker with access to the KNX network, or physical access to the device, can set a BCU key and lock the device, preventing legitimate users from resetting access. The issue can cause device availability loss and disrupt KNX installations.

KNX Connection Authorization Option 1 is a security mechanism in KNX building automation systems that controls access to devices by using a shared key (BCU key). It helps prevent unauthorized configuration changes, but weaker implementations can allow attackers to lock devices if they obtain network access.

The flaw CVE-2026-46817 affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP. Oracle fixed the issue in last month’s Critical Patch Update and urges customers to apply the patches immediately. In early July, Defused Cyber researchers warned that this vulnerability is being actively exploited.

Defused Cyber did not disclose technical details about the attacks that exploited the flaw or the motivation of the attackers.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to urgently fix the Oracle flaw by July 18, 2026, and address the KNX Association KNX Protocol Connection Authorization Option 1 flaw by July 29, 2026

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters

What Happened

  • On 9 June 2026, the University of Nottingham was listed as a victim on the ShinyHunters Tor data leak site.
  • The attackers leaked over 40GB of billing and payment records, student finance data, and campus portal exports from the University of Nottingham and its Malaysia and China campuses.
  • The data stolen includes contact information, transaction amounts, IP addresses, full names, home addresses, postcodes, email addresses, phone numbers, dates of birth, and other internal campus data.
  • Further analysis of the leaked data by Have I Been Pwned revealed it also contained over 455,000 unique email addresses along with extensive personal information including ethnicities, disabilities, and passport numbers.
  • On 10 June 2026, security researcher @nahamike01 uncovered an exposed server belonging to ShinyHunters and found them targeting Oracle PeopleSoft servers using MeshCentral agents. Plus, analysis the bash_history logs on the server uncovered SSH connections to the IP address hosting the ShinyHunters Tor data leak site.
  • On 11 June 2026, Mandiant and Google Threat Intelligence Group (GTIG) disclosed they have observed active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure via a zero-day now tracked as CVE-2026-35273, a critical remote code execution (RCE) vulnerability (CVSS 9.8).

Analyst Comment
ShinyHunters is a prolific feature of current threat landscape. This adversary appears to have a particular focus on the educational sector. Last month in May 2026, ShinyHunters targeted another provider of educational software: Instructure Canvas. A number of other UK universities were also impacted by the Instructure breach.

The education sector in the US and UK has suffered repeated, significant data breaches in recent years. In January 2025, BleepingComputer reported that PowerSchools, a cloud-based software provider, suffered a breach whereby the data of 62.4 million students and 9.5 million teachers was exfiltrated. Also in June 2026, the University of Oxford also disclosed a data breach impacting its CareerConnect platform. Separately, 13 schools in Powys county in Wales were impacted by a data breach in April 2026.

After the Oracle E-Business Suite zero-day campaign by CLOP in October 2025, this campaign by ShinyHunters against Oracle PeopleSoft is yet another blow for Oracle. Google identified over 100 exposed organisations, and noted that 68% are academic institutions, including universities and colleges worldwide. More are likely to have been victimised by ShinyHunters and listed on their Tor data leak site in the coming weeks.

Defensive Takeaways

  • Patch Oracle PeopleSoft: Internet-facing applications, such as file transfer servers or cloud-based software need to be prioritised for patches and updates. Checking the integrity of such systems while patching is also key to finding undetected compromises. Proactively ingesting event logs and threat hunting for suspicious activities involving these systems is also key to prevent breaches.
  • Prioritise Education Software Security: Education sector firms or cybersecurity companies with education sector clients must react to the elevated threat, by pen-testing, threat hunting, and threat intelligence sharing. Cybercriminal adversaries like ShinyHunters often exploit internet-facing applications or use stolen credentials for initial access. It is therefore critical to focus on these tactics, techniques, and procedures (TTPs) to prevent their attacks.
  • Follow the Data Breach Alert Playbook: Impacted victims must begin to rotate credentials, and start the laborious task of requesting new identity documents and codes like national insurance numbers or passports. It is also worth investing in some credit monitoring services as well to prevent loans being taken out in your name.

Relevant Sources

  1. https://x.com/politlcsuk/status/2064699766215164241
  2. https://www.dailymail.com/news/article-15889587/University-Nottingham-data-major-hack-cybercriminal.html
  3. https://www.bbc.co.uk/news/articles/ckg0lkp042zo
  4. https://www.bbc.co.uk/news/articles/cnv93j9pv78o
  5. https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-raids-nottingham-uni-for-student-alumni-data/5253961

Relevant CTI Resources

  1. https://www.ransomware.live/id/bm90dGluZ2hhbS5hYy51a0BzaGlueWh1bnRlcnM
  2. https://haveibeenpwned.com/Breach/UniversityOfNottingham
  3. https://x.com/nahamike01/status/2064559568018186745
  4. https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit 

Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed

Oracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed.

This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited. The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP. Oracle fixed the issue in last month’s Critical Patch Update and urges customers to apply the patches immediately.

Defused Cyber did not disclose technical details about the attacks that exploited the flaw or the motivation of the attackers.

🚨 CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited

Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots

This vulnerability has no known previous exploitation and no public POC code… pic.twitter.com/qL4dgPvoMP

— Defused (@DefusedCyber) June 29, 2026

Now, Internet monitoring firm Shadowserver counts roughly 950 EBS instances still reachable from the public internet, most of them in the United States. Nobody knows how many of those have been patched.

“We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with @ValidinLLC. Around 950 exposed instances now seen globally (no vulnerability assessment).” reads the post published by The Shadowserver Foundation.

We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with @ValidinLLC. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by @DefusedCyber pic.twitter.com/gghdTt5b1X

— The Shadowserver Foundation (@Shadowserver) July 1, 2026

Despite researchers confirming active exploitation of the vulnerabilities, Oracle hasn’t officially flagged this vulnerability as exploited in the wild.

If your organization runs Oracle EBS and hasn’t applied it, that’s the immediate priority. If a public-facing EBS instance is genuinely required for business operations, verify it’s patched before checking anything else on your list today. If it doesn’t need to be internet-facing, take it off the internet.

Shadowserver’s scan suggests the exposed population is not small, and active exploitation without a public proof-of-concept means the attacker community is already ahead of most defenders on this one.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Oracle E-Business)

Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817

Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments.

A critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited in the wild, according to cybersecurity firm Defused Cyber.

“CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots.” reads the post on X published by the cybersecuriyt firm. “This vulnerability has no known previous exploitation and no public POC code exists.”

🚨 CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited

Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots

This vulnerability has no known previous exploitation and no public POC code… pic.twitter.com/qL4dgPvoMP

— Defused (@DefusedCyber) June 29, 2026

The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP. Oracle fixed the issue in last month’s Critical Patch Update and urges customers to apply the patches immediately.

Defused Cyber did not disclose technical details about the attacks that exploited the flaw or the motivation of the attackers.

In mid June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Oracle PeopleSoft Enterprise PeopleTools flaw, tracked as CVE-2026-35273 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.

Oracle PeopleSoft Enterprise PeopleTools is the underlying technology platform used to build, run, administer, and customize Oracle PeopleSoft applications.

The flaw CVE-2026-35273 is a remote code execution vulnerability in Oracle PeopleSoft’s Environment Management component. No authentication required. No user interaction required. Just network access to the Environment Management Hub endpoint and you can take over the server.

Mandiant and Google’s Threat Intelligence Group published an analysis of an active ShinyHunters campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited. The gap matters: the activity ran from May 27 to June 9, meaning every organization hit during those two weeks was dealing with a zero-day, a flaw with no available patch and no official vendor warning. Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – Oracle,  hacking)

Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla and Oracle — fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.

As it does on the second Tuesday of every month, Microsoft today released software updates to address at least 118 security vulnerabilities in its various Windows operating systems and other products. Remarkably, this is the first Patch Tuesday in nearly two years that Microsoft is not shipping any fixes to deal with emergency zero-day flaws that are already being exploited. Nor have any of the flaws fixed today been previously disclosed (potentially giving attackers a heads up in how to exploit the weakness).

Sixteen of the vulnerabilities earned Microsoft’s most-dire “critical” label, meaning malware or miscreants could abuse these bugs to seize remote control over a vulnerable Windows device with little or no help from the user. Rapid7 has done much of the heavy lifting in identifying some of the more concerning critical weaknesses this month, including:

  • CVE-2026-41089: A critical stack-based buffer overflow in Windows Netlogon that offers an attacker SYSTEM privileges on the domain controller. No privileges or user interaction are required, and attack complexity is low. Patches are available for all versions of Windows Server from 2012 onwards.
  • CVE-2026-41096: A critical RCE in the Windows DNS client implementation worthy of attention despite Microsoft assessing exploitation as less likely.
  • CVE-2026-41103: A critical elevation of privilege vulnerability that allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID. Microsoft expects that exploitation is more likely.

May’s Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws. Microsoft was among a few dozen tech giants given access to a “Project Glasswing,” a much-hyped AI capability developed by Anthropic that appears quite effective at unearthing security vulnerabilities in code.

Apple, another early participant in Project Glasswing, typically fixes an average of 20 vulnerabilities each time it ships a security update for iOS devices, said Chris Goettl, vice president of product management at Ivanti. On May 11, Apple shipped updates to address at least 52 vulnerabilities and backported the changes all the way to iPhone 6s and iOS 15.

Last month, Mozilla released Firefox 150, which resolved a whopping 271 vulnerabilities that were reportedly discovered during the Glasswing evaluation.

“Since Firefox 150.0.0 released, they have been on a more aggressive weekly cadence for security updates including the release of Firefox 150.0.3 on May Patch Tuesday resolving between three to five CVEs in each release,” Goettl said.

The software giant Oracle likewise recently increased its patch pace in response to their work with Glasswing. In its most recent quarterly patch update, Oracle addressed at least 450 flaws, including more than 300 fixes for remotely exploitable, unauthenticated flaws. But at the end of April, Oracle announced it was switching to a monthly update cycle for critical security issues.

On May 8, Google started rolling out updates to its Chrome browser that fixed an astonishing 127 security flaws (up from just 30 the previous month). Chrome automagically downloads available security updates, but installing them requires fully restarting the browser.

If you encounter any weirdness applying the updates from Microsoft or any other vendor mentioned here, feel free to sound off in the comments below. Meantime, if you haven’t backed up your data and/or drive lately, doing that before updating is generally sound advice. For a more granular look at the Microsoft updates released today, checkout this inventory by the SANS Internet Storm Center.

❌