logo

CISA orders feds to patch actively exploited Oracle flaw by Saturday

ID: f833d943-830b-53f4-a34d-9cc2984d38d3

STIX ID: report--f833d943-830b-53f4-a34d-9cc2984d38d3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Sergiu Gatlan

...
...

CISA ordered federal agencies to urgently patch a critical Oracle E-Business Suite flaw (CVE-2026-46817, CVSS 9.8) in the Oracle Payments/File Transmission component after vendor patches were released and reports of active exploitation surfaced; security firm Defused observed exploitation on honeypots and Shadowserver reports over 1,000 Internet-exposed EBS instances, prompting inclusion on CISA's known exploited vulnerabilities list and a mandatory patch deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.