bleeping-computer · Crawled Jul 16, 2026

CISA orders feds to patch actively exploited Oracle flaw by Saturday

Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability, CVE-2026-46817, in Oracle E-Business Suite (EBS) by July 18, 2026, due to active exploitation in the wild. The flaw resides in the File Transmission component of Oracle Payments and allows unauthenticated attackers to take over systems via HTTP. Threat intelligence firm Defused confirmed exploitation after observing attacks on honeypots, despite the absence of public proof-of-concept code. CISA emphasizes prompt patching to prevent compromise of federal systems.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.