bleeping-computer · Crawled Jul 16, 2026
CISA orders feds to patch actively exploited Oracle flaw by Saturday
Read original article ↗AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability, CVE-2026-46817, in Oracle E-Business Suite (EBS) by July 18, 2026, due to active exploitation in the wild. The flaw resides in the File Transmission component of Oracle Payments and allows unauthenticated attackers to take over systems via HTTP. Threat intelligence firm Defused confirmed exploitation after observing attacks on honeypots, despite the absence of public proof-of-concept code. CISA emphasizes prompt patching to prevent compromise of federal systems.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.