Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed

2026-07-01T20:51:43Z72f827b7ca402057bbecba44e3818b4d9b9074122cd2668a3224ae4b45d96b1b
CVE-2026-33825CVE-2026-46817CVE-2026-48558LSHIYactive-exploitationaflac-japanai-assisted-vuln-discoveryappleazure-clibluehammerbotnetcisacybercrime-forumdata-breachguardfallknown-exploited-vulnerabilitiesopen-source-ai-agentsoracle-e-business-suitepassword-sprayransomwarerustducksimplehelpwebkitxss.is

What happened

This feed reports multiple high-impact security developments: a critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS ~9.8) is under active exploitation with ~950 internet-facing vulnerable instances; SimpleHelp authentication-bypass (CVE-2026-48558, CVSS 10.0) was added to CISA’s Known Exploited Vulnerabilities catalog; and BlueHammer (CVE-2026-33825) is being used in real-world ransomware attacks to achieve SYSTEM privileges via Microsoft Defender. Other notable items: a massive Azure CLI password-spray campaign (LSHIY) spanning 64 organizations with ~81 million login attempts and 78账户

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
72f827b7ca402057bbecba44e3818b4d9b9074122cd2668a3224ae4b45d96b1b
Enrichment time
2026-07-01T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed · Baitaphish