FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Oracle WebLogic Server Authentication Bypass CVE-2024-21182

CVE-2024-21182 is a critical authentication bypass vulnerability within the Oracle WebLogic Server Core component. This flaw allows unauthenticated attackers to circumvent security mechanisms via the T3 and IIOP protocols, potentially enabling a full unauthenticated system takeover. Due to confirmed active exploitation in the wild, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, imposing a mandatory June 4 remediation deadline for federal entities. Failure to patch immediately risks large-scale unauthorized access, confidentiality compromise, and total control of affected WebLogic environments.

Critical Unauthenticated Remote Takeover in Oracle E-Business Suite CVE-2026-46817

CVE-2026-46817 is a critical authentication bypass vulnerability residing within the Oracle Payments component of the Oracle E-Business Suite (EBS). Rated with a CVSS v3.1 score of 9.8, this flaw permits unauthenticated remote attackers to circumvent security protocols and achieve full administrative or root-level control over the EBS instance. Research from Defused Cyber confirms that the vulnerability is currently being exploited in the wild. By targeting specific vulnerable API endpoints, adversaries can compromise the integrity of corporate financial records, payment processing workflows, and sensitive enterprise PII, posing a systemic risk of ransomware deployment and long-term persistence within ERP environments.

Zero-Day Exploitation of Oracle PeopleSoft by UNC6240

UNC6240 (ShinyHunters) conducted a zero-day exploitation campaign targeting Oracle PeopleSoft (PeopleTools 8.61 and 8.62) between May 27 and June 9, 2026. The actors exploited CVE-2026-35273, a critical Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in the Updates Environment Management component, to achieve unauthenticated Remote Code Execution (RCE). Following initial access, the group deployed MeshCentral remote management agents disguised as Microsoft Azure services to maintain persistence and perform reconnaissance. Data was compressed using 'zstd' and exfiltrated for extortion on the ShinyHunters Data Leak Site. CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on June 12, 2026, following widespread targeting of the higher education sector.

Oracle E-Business Suite: CVE-2025-61882 RCE and CL0P Ransomware Exploitation

CVE-2025-61882 is a critical unauthenticated remote code execution (RCE) vulnerability in Oracle E-Business Suite (EBS) carrying a CVSS v3.1 score of 9.8. The flaw allows network-based attackers to bypass authentication and execute arbitrary commands with high privileges on on-premises EBS installations. Active exploitation by the CL0P ransomware group utilizes this zero-day for initial access, facilitating large-scale exfiltration of sensitive financial and HR data. This activity precedes the deployment of ransomware for double-extortion. Immediate remediation requires the application of the Oracle July 2025 Critical Patch Update (CPU) to prevent full infrastructure compromise and subsequent regulatory breaches.


LINK COPIED TO CLIPBOARD