Find notable cyber news and cases, enriched with sources, timelines, and signals.

Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)

Security Patch Release
First reported
Last updated
Happening score
H score 53
2 unique sources, 2 articles

Summary

Hide ▲

Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an unauthenticated attacker via HTTP take over susceptible instances. Oracle had already shipped patches for versions 12.2.3 through 12.2.15 as part of the update, and Defused Cyber later reported active exploitation in the wild against honeypots.

Related Happenings

Oracle PeopleSoft broad zero-day exploitation campaign

Exploitation Wave
H score82 First: 29.06.2026 13:00 Last: 29.06.2026 13:00 Sources 1

About this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...

CISA orders federal patching of Oracle WebLogic CVE-2024-21182

Public Sector Action
H score53 First: 02.06.2026 15:40 Last: 02.06.2026 15:40 Sources 1

About this happening: CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...

Initial-access handoff time drops to 22 seconds across Mandiant investigations

Trend
H score26 First: 23.03.2026 17:00 Last: 23.03.2026 17:00 Sources 1

About this happening: Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...

Oracle security patch release for CVE-2026-21992

Security Patch Release
H score44 First: 21.03.2026 12:24 Last: 21.03.2026 12:24 Sources 1

About this happening: Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...

Barts Health NHS Trust invoice leak on Cl0p leak portal

Data Leak
H score38 First: 05.12.2025 20:55 Last: 05.12.2025 20:55 Sources 1

About this happening: The Barts Health NHS Trust data leak became public when Cl0p posted stolen invoice files on its dark-web leak portal, exposing full names and addresses linked...

Latest development: 08.12.2025 11:30

Barts Health NHS Trust is seeking a High Court order to stop the sharing, publication or use of invoice files stolen from its Oracle E-business Suite (EBS) database; the trust says Cl0p posted the files on the dark web, and it is working with NHS England, the National Cyber Security Centre, the Metropolitan Police and regulators including the Information Commissioner’s Office while its clinical systems remain unaffected.

Timeline

  1. 29.06.2026 16:46 3 articles · 16d ago

    Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)

    Initial Disclosure

    Oracle issued the May 2026 Critical Security Patch Update for CVE-2026-46817 in Oracle E-Business Suite, directing customers to patch immediately after the flaw was identified as a takeover risk.

    Show sources