Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed

2026-07-02T02:51:41Zb4ca3ed3928b022d185b70b354256fff3f66ef539b1c917c2c50355d5df557d1
aflac-japanazure-clibluehammercisa-kevcve-2026-33825cve-2026-46817cve-2026-48558cybercrime-forum-takedowndata-breachguardfall-ai-agentsoracle-e-business-suitepassword-sprayransomwarerustduck-botnetsimplehelpwebkit-patches

What happened

Multiple high-risk incidents and vulnerabilities reported: Oracle E-Business Suite critical flaw CVE-2026-46817 is being actively exploited in the wild, with ~950 internet-facing Oracle Payments instances still exposed. CISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to escalate to SYSTEM via Microsoft Defender. CISA also added a critical SimpleHelp authentication-bypass (CVE-2026-48558, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Other notable items include a large Azure CLI password-spray campaign (LSHIY) affecting dozens of organizations, the small

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b4ca3ed3928b022d185b70b354256fff3f66ef539b1c917c2c50355d5df557d1
Enrichment time
2026-07-02T02:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.