Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
2026-07-01T20:51:43Z•72f827b7ca402057bbecba44e3818b4d9b9074122cd2668a3224ae4b45d96b1b
CVE-2026-33825CVE-2026-46817CVE-2026-48558LSHIYactive-exploitationaflac-japanai-assisted-vuln-discoveryappleazure-clibluehammerbotnetcisacybercrime-forumdata-breachguardfallknown-exploited-vulnerabilitiesopen-source-ai-agentsoracle-e-business-suitepassword-sprayransomwarerustducksimplehelpwebkitxss.is
What happened
This feed reports multiple high-impact security developments: a critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS ~9.8) is under active exploitation with ~950 internet-facing vulnerable instances; SimpleHelp authentication-bypass (CVE-2026-48558, CVSS 10.0) was added to CISA’s Known Exploited Vulnerabilities catalog; and BlueHammer (CVE-2026-33825) is being used in real-world ransomware attacks to achieve SYSTEM privileges via Microsoft Defender. Other notable items: a massive Azure CLI password-spray campaign (LSHIY) spanning 64 organizations with ~81 million login attempts and 78账户
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 72f827b7ca402057bbecba44e3818b4d9b9074122cd2668a3224ae4b45d96b1b
- Enrichment time
- 2026-07-01T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.