The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite (EBS) financial application. Discovered in the File Transmission component of EBS's Oracle Payments product and tracked as CVE-2026-46817, this security flaw allows unauthenticated threat actors with HTTP network access to take over vulnerable systems in low-complexity attacks. Oracle released security updates to address the security issue with its May 2026 Critical Security Patch Update, urging customers to patch their systems immediately. "In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches," the company warned at the time. "Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay." While Oracle has not yet flagged CVE-2026-46817 as exploited in the wild, threat intelligence company Defused said on June 29 that malicious actors had begun exploiting it in the wild. "CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited. Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots. This vulnerability has no known previous exploitation and no public POC code exists," Defused noted. Internet security watchdog Shadowser...
CISA orders feds to patch actively exploited Oracle flaw by Saturday
BleepingComputer
·Sergiu Gatlan
·Published Jul 16, 2026
·Updated
Affected Software
2 affected components
Oracle E-Business Suite (EBS)
Oracle Oracle Payments (File Transmission component)
Frequently Asked Questions
1
What is the main topic of this article?
The main topic of this article is the order by CISA for federal agencies to patch a critical vulnerability in Oracle E-Business Suite due to active exploitation.
2
What security implications are discussed?
The article discusses the implications of ongoing attacks exploiting a critical vulnerability that could compromise federal systems if not patched.
3
What products or software are affected?
The affected products include Oracle E-Business Suite (EBS) and the Oracle Payments File Transmission component.
4
What is the deadline for federal agencies to apply the security patch?
Federal agencies have been ordered to apply the security patch by Saturday following the article's publication.
5
What type of vulnerability is mentioned in the article?
The article mentions a critical vulnerability that has been categorized as exploited in active attacks.