Published Tuesday, August 25, 2026 at 04:34 AM PT

<strong>CRITICAL: Oracle WebLogic & E-Business Suite Actively Exploited β€” Unauthenticated Remote Access</strong>

BLUF: Unauthenticated remote attackers are actively exploiting critical vulnerabilities in Oracle WebLogic (CVE-2026-21962) and Oracle E-Business Suite (CVE-2026-46817) to gain unauthorized access to sensitive data. CISA has issued formal advisories. Organizations running these products must patch immediately or restrict network access.

DETAILS:

  • Two CVEs confirmed under active exploit: CVE-2026-21962 (Oracle WebLogic) and CVE-2026-46817 (Oracle E-Business Suite) β€” both critical severity, both allow unauthenticated remote access to critical data.
  • Exploitation preceded public disclosure: Attackers were exploiting these flaws in the wild before public exploit code was released, indicating coordinated or sophisticated threat activity.
  • CISA mandate issued: U.S. CISA has issued formal warnings and is mandating immediate remediation for federal agencies and contractors.
  • Scope extends to PeopleSoft: Related zero-day in Oracle PeopleSoft is also being exploited in active data theft campaigns.
  • SQL injection vector confirmed: At least one attack path involves SQL injection allowing malware placement inside Oracle Database backends.

IMPACT:

  • Affected systems: Oracle WebLogic, E-Business Suite, PeopleSoft deployments across enterprise and government sectors.
  • Attack surface: Unauthenticated β€” no credentials, VPN, or insider access required; attacks originate from the internet.
  • Data at risk: Financial records, ERP data, payroll, operational secrets, customer information β€” anything stored in affected databases.
  • Scale: Critical infrastructure, Fortune 500 companies, government agencies confirmed in targeting.

RECOMMENDED ACTIONS:

  1. Inventory all Oracle WebLogic, E-Business Suite, and PeopleSoft instances immediately.
  2. Apply emergency security patches from Oracle’s latest advisories (CVE-2026-21962, CVE-2026-46817).
  3. Restrict network access to these systems to trusted internal subnets only; disable external connectivity if possible.
  4. Monitor for exploitation indicators: unexpected remote connections, unauthenticated database queries, SQL injection attempts in logs.
  5. Check CISA’s website for detailed remediation steps and indicator lists.
  6. If patching is delayed, implement Web Application Firewall (WAF) rules to block exploitation attempts.

SOURCES:

The Hacker News, BleepingComputer, SecurityWeek, The Register, CSO Online, CISA Alerts


Recent high-severity events at publish time:

Recent high-severity events