FeedVulnerabilityOver 900 Oracle E-Business instances exposed to ongoing atta...
VulnerabilityBleeping Computer
9.8CRITICAL

Over 900 Oracle E-Business instances exposed to ongoing attacks

📅 1 July 2026 at 12:30 UTC📰 Bleeping ComputerView original source ↗
Over 900 Oracle E-Business instances exposed to ongoing attacks

Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Over 900 Oracle E-Business Suite instances have been found exposed online, with threat actors actively exploiting a critical security flaw (CVE-2026-46817) that allows unauthenticated attackers to take over vulnerable systems through low-complexity attacks.

⚙️Technical Details
CVEs
CVE-2026-46817CVE-2024-21182CVE-2026-35273CVE-2025-61882Affected Systems: Oracle E-Business SuiteAttack Vectors: NETWORK, HTTP
Affected Systems
Oracle E-Business Suite
Attack Vectors
NETWORK, HTTP
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Patch Oracle E-Business Suite instances with the May 2026 Critical Security Patch Update
2Monitor network traffic for suspicious activity related to CVE-2026-46817
3Implement additional security controls, such as intrusion detection and prevention systems
📦Affected Products
Oracle E-Business SuiteOracle Weblogic ServerOracle Peoplesoft Enterprise PeopletoolsOracle Concurrent Processing
🔐NVD Verified DataVERIFIED
CVE-2026-46817CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306CWE-269CWE-287
Affected Products (CPE)
Oracle E-Business Suite
CVE-2024-21182CVSS 7.5HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products (CPE)
Oracle Weblogic Server
CVE-2026-35273CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
Affected Products (CPE)
Oracle Peoplesoft Enterprise Peopletools
CVE-2025-61882CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected Products (CPE)
Oracle Concurrent Processing

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed