FeedVulnerabilityHackers now exploit critical Oracle E-Business flaw in attac...
VulnerabilityBleeping Computer
9.8CRITICAL

Hackers now exploit critical Oracle E-Business flaw in attacks

📅 29 June 2026 at 13:46 UTC📰 Bleeping ComputerView original source ↗
Hackers now exploit critical Oracle E-Business flaw in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Attackers are exploiting a critical Oracle E-Business Suite vulnerability (CVE-2026-46817) that enables unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks, affecting multiple U.S. universities and other organizations.

⚙️Technical Details
Affected Systems
Oracle E-Business SuiteOracle WebLogic ServerPeopleSoft Enterprise PeopleTools
Attack Vectors
HTTPNETWORK
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Apply security patches to Oracle E-Business Suite immediately
2Monitor network traffic for suspicious HTTP requests
3Implement additional security controls, such as intrusion detection systems
📦Affected Products
Oracle E-Business SuiteOracle Concurrent ProcessingOracle Weblogic ServerOracle Peoplesoft Enterprise PeopletoolsOracle WebLogic ServerPeopleSoft Enterprise PeopleTools
🔐NVD Verified DataVERIFIED
CVE-2026-46817CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306CWE-269CWE-287
Affected Products (CPE)
Oracle E-Business Suite
CVE-2025-61882CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected Products (CPE)
Oracle Concurrent Processing
CVE-2024-21182CVSS 7.5HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products (CPE)
Oracle Weblogic Server
CVE-2026-35273CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
Affected Products (CPE)
Oracle Peoplesoft Enterprise Peopletools

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed