Published Tuesday, August 25, 2026 at 04:34 AM PT

BLUF: Unauthenticated remote attackers are actively exploiting critical vulnerabilities in Oracle WebLogic (CVE-2026-21962) and Oracle E-Business Suite (CVE-2026-46817) to gain unauthorized access to sensitive data. CISA has issued formal advisories. Organizations running these products must patch immediately or restrict network access.
DETAILS:
- Two CVEs confirmed under active exploit: CVE-2026-21962 (Oracle WebLogic) and CVE-2026-46817 (Oracle E-Business Suite) β both critical severity, both allow unauthenticated remote access to critical data.
- Exploitation preceded public disclosure: Attackers were exploiting these flaws in the wild before public exploit code was released, indicating coordinated or sophisticated threat activity.
- CISA mandate issued: U.S. CISA has issued formal warnings and is mandating immediate remediation for federal agencies and contractors.
- Scope extends to PeopleSoft: Related zero-day in Oracle PeopleSoft is also being exploited in active data theft campaigns.
- SQL injection vector confirmed: At least one attack path involves SQL injection allowing malware placement inside Oracle Database backends.
IMPACT:
- Affected systems: Oracle WebLogic, E-Business Suite, PeopleSoft deployments across enterprise and government sectors.
- Attack surface: Unauthenticated β no credentials, VPN, or insider access required; attacks originate from the internet.
- Data at risk: Financial records, ERP data, payroll, operational secrets, customer information β anything stored in affected databases.
- Scale: Critical infrastructure, Fortune 500 companies, government agencies confirmed in targeting.
RECOMMENDED ACTIONS:
- Inventory all Oracle WebLogic, E-Business Suite, and PeopleSoft instances immediately.
- Apply emergency security patches from Oracle’s latest advisories (CVE-2026-21962, CVE-2026-46817).
- Restrict network access to these systems to trusted internal subnets only; disable external connectivity if possible.
- Monitor for exploitation indicators: unexpected remote connections, unauthenticated database queries, SQL injection attempts in logs.
- Check CISA’s website for detailed remediation steps and indicator lists.
- If patching is delayed, implement Web Application Firewall (WAF) rules to block exploitation attempts.
SOURCES:
The Hacker News, BleepingComputer, SecurityWeek, The Register, CSO Online, CISA Alerts
Recent high-severity events at publish time:

