Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
2026-07-02T02:51:41Z•b4ca3ed3928b022d185b70b354256fff3f66ef539b1c917c2c50355d5df557d1
aflac-japanazure-clibluehammercisa-kevcve-2026-33825cve-2026-46817cve-2026-48558cybercrime-forum-takedowndata-breachguardfall-ai-agentsoracle-e-business-suitepassword-sprayransomwarerustduck-botnetsimplehelpwebkit-patches
What happened
Multiple high-risk incidents and vulnerabilities reported: Oracle E-Business Suite critical flaw CVE-2026-46817 is being actively exploited in the wild, with ~950 internet-facing Oracle Payments instances still exposed. CISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to escalate to SYSTEM via Microsoft Defender. CISA also added a critical SimpleHelp authentication-bypass (CVE-2026-48558, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Other notable items include a large Azure CLI password-spray campaign (LSHIY) affecting dozens of organizations, the small
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- b4ca3ed3928b022d185b70b354256fff3f66ef539b1c917c2c50355d5df557d1
- Enrichment time
- 2026-07-02T02:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.