CISA orders feds to patch actively exploited Oracle flaw by Saturday

Federal Agencies Ordered to Patch Critical Oracle Flaw by Saturday Amid Ongoing Attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to federal agencies, instructing them to patch a critical vulnerability in the Oracle E-Business Suite financial application by this coming Saturday. The move comes as threat actors continue to exploit the flaw, which allows unauthenticated attackers with HTTP network access to take over vulnerable systems.

The vulnerability, tracked as CVE-2026-46817, was discovered in the File Transmission component of Oracle Payments and is considered a high-risk issue due to its ease of exploitation. Oracle first patched the flaw back in May with its Critical Security Patch Update, urging customers to apply the fix immediately. However, it appears that many organizations have yet to do so.

Threat intelligence company Defused reported earlier this month that malicious actors had begun exploiting the vulnerability in the wild, noting that no public proof-of-concept (POC) code exists and that the flaw has not been previously exploited. This suggests that attackers are using novel techniques or custom-made exploits to take advantage of the weakness.

The CISA’s directive is part of its ongoing efforts to protect federal agencies from cyber threats. The agency has identified over 1,000 Internet-exposed Oracle EBS instances, with more than half located in the United States. However, it is unclear how many of these instances are honeypots or have already been secured against ongoing attacks.

This latest incident highlights the importance of timely patching and vulnerability management. As CISA noted, vulnerabilities like CVE-2026-46817 are frequent attack vectors for malicious actors and pose significant risks to the federal enterprise. This is not an isolated issue – in recent months, the agency has also flagged a slew of other Oracle flaws that have been exploited in the wild.

For organizations still running unpatched versions of Oracle EBS, this serves as a stark reminder to prioritize security updates and ensure their systems are protected against known vulnerabilities. With threat actors continuing to exploit CVE-2026-46817, it’s crucial for administrators to take immediate action and apply available patches without delay.

Practically speaking, organizations should review their patch management processes and ensure that all necessary updates are applied in a timely manner. This includes keeping software up-to-date, monitoring system logs for suspicious activity, and conducting regular vulnerability scans to identify potential weaknesses. By doing so, they can minimize the risk of falling victim to ongoing attacks exploiting this critical flaw.


Source: Bleeping Computer — 2026-07-16