Federal Agencies Ordered to Patch Critical Oracle Vulnerability by Saturday
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive to all federal agencies, requiring them to patch a critical vulnerability in the Oracle E-Business Suite (EBS) financial application by this Saturday. The flaw, tracked as CVE-2026-46817, allows unauthenticated attackers with HTTP network access to take over vulnerable systems, and it’s already being exploited in the wild.
The vulnerability was discovered in the File Transmission component of Oracle Payments, a product within the EBS suite. In May, Oracle released security updates to address the issue as part of its Critical Security Patch Update. However, many customers failed to apply these patches, leaving their systems exposed to potential attacks. Oracle warned at the time that attackers could succeed due to unpatched vulnerabilities.
Threat intelligence company Defused observed malicious actors exploiting CVE-2026-46817 in early June, even though Oracle had not yet flagged it as exploited in the wild. Since then, the number of exposed instances has grown significantly, with internet security watchdog Shadowserver tracking over 1,000 Internet-exposed Oracle EBS instances – more than half of which are located in the United States.
CISA’s decision to order federal agencies to patch vulnerable systems by Saturday is a clear indication that the agency takes this threat seriously. The directive comes as part of Binding Operational Directive (BOD) 26-04, which requires US government agencies to prioritize security patches and updates for critical vulnerabilities. This is not an isolated incident; CISA has previously ordered federal agencies to patch other Oracle vulnerabilities, including a SSRF flaw in EBS and a high-severity WebLogic Server flaw.
The fact that this vulnerability has been exploited in the wild and is still being targeted by attackers highlights the importance of prioritizing security patches and updates. Over the last several years, CISA has flagged 43 security issues across various Oracle products that have been exploited in the wild, with many of these vulnerabilities remaining unpatched for extended periods.
To mitigate this risk, it’s essential for organizations to prioritize patch management and ensure that all systems are up-to-date with the latest security updates. This includes not only applying patches promptly but also regularly testing and verifying their effectiveness. By taking proactive measures to secure their systems, organizations can reduce the likelihood of being targeted by attackers and minimize the impact of potential attacks.
As CISA continues to prioritize the security of federal agencies and critical infrastructure, it’s crucial for all organizations to take a similar approach to patch management. Regularly testing every layer of your environment before attackers do is key to preventing successful breaches. By doing so, you can ensure that your systems are secure and protected against known vulnerabilities, reducing the risk of exploitation and minimizing the impact of potential attacks.
Source: Bleeping Computer — 2026-07-16