A recent proof-of-concept by security firm TantoSec has demonstrated how a vulnerability in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution (RCE). This exploit takes advantage of a 'padding oracle' issue with AES-CBC encryption, but it's important to note that it only affects applications configured in a specific, non-default way. Progress, the vendor of Telerik, patched this vulnerability back in July, and so far, there are no confirmed reports of this exploit being used in real-world attacks. Organizations using Telerik UI should ensure their configurations are secure and apply any relevant updates to mitigate potential risks.
Articles tagged "Oracle"
Found 44 articles
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting Gitea, an open-source platform, to its Known Exploited Vulnerabilities catalog. This flaw is linked to potential exploits that could compromise the security of Gitea installations. It is vital for organizations using Gitea to address this vulnerability promptly to prevent unauthorized access or data breaches. The inclusion in CISA's catalog indicates that this issue is being actively exploited or poses a significant threat to users. Organizations should prioritize applying security updates and monitoring their systems closely to mitigate risks.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified vulnerability in Oracle WebLogic to its list of actively exploited security issues. This vulnerability allows attackers to gain access to core business applications within an enterprise, posing significant risks to sensitive data and operations. Organizations using Oracle WebLogic middleware need to be particularly vigilant, as this exploitation could lead to severe disruptions and data breaches. Experts recommend that affected companies prioritize patching this vulnerability to safeguard their systems. The urgency is underscored by the fact that attackers are actively exploiting this flaw.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in Oracle's HTTP Server and Weblogic Server Proxy Plug-in to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-21962, carries a maximum severity score of 10.0, indicating it is a critical risk for users. The vulnerability allows unauthenticated attackers to exploit the affected systems, which could potentially lead to unauthorized access and control. Organizations using these Oracle products should take immediate action to assess their systems and implement necessary security measures to mitigate this risk. The inclusion in CISA's catalog suggests that this vulnerability is being actively targeted by malicious actors, making swift remediation essential.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, specifically CVE-2026-21962, which affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. This vulnerability involves improper access control and has been linked to active exploitation, making it a significant risk for federal agencies and other organizations. CISA's Binding Operational Directive (BOD) 26-04 mandates that federal agencies prioritize fixing high-risk vulnerabilities like this one, especially on publicly exposed systems. While the directive is aimed at federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Companies are urged to act swiftly to mitigate this risk and report any additional vulnerabilities for consideration in the KEV Catalog.
Oracle has released a significant security update for August 2026, addressing a total of 943 patches that fix over 1,000 vulnerabilities across two dozen of its products. Among these vulnerabilities, more than 460 are considered remotely exploitable, meaning attackers could potentially exploit them from a distance without physical access to the systems. This update is crucial for organizations using Oracle products, as ignoring these vulnerabilities could expose them to significant risks, including data breaches and system compromises. Users are advised to apply these patches promptly to safeguard their systems against potential attacks. The breadth of the vulnerabilities covered in this update highlights the ongoing need for vigilance in software security management.
Hackers have taken advantage of a SQL injection vulnerability to install a post-exploitation toolkit known as Khunt directly within an Oracle database. This breach allowed them to infiltrate a corporate network, raising serious concerns about the security of Oracle database systems. Organizations using Oracle databases need to be aware of this attack vector and ensure their systems are fortified against such vulnerabilities. SQL injection remains a common method for attackers, and this incident serves as a reminder of the importance of secure coding practices and regular security audits. Companies should prioritize patching known vulnerabilities and implementing robust security measures to protect sensitive data.
Estée Lauder has informed customers about a data breach that occurred due to a vulnerability in Oracle's E-Business Suite, which the company uses for its human resources operations. Hackers exploited this flaw, potentially compromising the personal data of affected individuals. While the specific details about the type of data accessed have not been disclosed, this incident raises concerns about the security of sensitive information within large organizations. Customers are advised to monitor their accounts for any unusual activity as the company works to address the breach. This incident serves as a reminder for businesses to ensure their software systems are regularly updated and secure against known vulnerabilities.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included new vulnerabilities in its Known Exploited Vulnerabilities catalog, specifically targeting the KNX Protocol Connection Authorization Option 1 from the KNX Association and various flaws related to Oracle products. This update is crucial as it indicates that these vulnerabilities could be actively exploited by attackers, posing risks to organizations using affected systems. The inclusion of these vulnerabilities serves as a warning to IT departments and security teams to prioritize patching and mitigation efforts. Notably, CISA also added vulnerabilities from SonicWall and Microsoft to the catalog, emphasizing the ongoing need for vigilance in cybersecurity practices. Companies should review their systems and apply necessary updates to safeguard against potential attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies address a serious vulnerability in the Oracle E-Business Suite by Saturday. This flaw is being actively exploited in the wild, posing risks to financial operations managed through the software. Agencies are urged to take immediate action to protect their systems from potential attacks that could compromise sensitive financial data. The urgency of this directive reflects the critical nature of the vulnerability and the potential impact on government operations if left unaddressed.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The first, CVE-2023-4346, affects the KNX Protocol Connection Authorization Option 1, which has an overly restrictive account lockout mechanism, making it a target for attackers. The second, CVE-2026-46817, involves improper privilege management in Oracle E-Business Suite. These vulnerabilities pose significant risks, particularly to federal agencies, which are required by CISA's Binding Operational Directive 26-04 to prioritize rapid remediation of high-risk vulnerabilities. While this directive specifically applies to federal agencies, CISA encourages all organizations to adopt similar practices. Organizations that identify exploited vulnerabilities not listed in the KEV Catalog can submit them for potential inclusion.
Help Net Security
Last week, vulnerabilities in SimpleHelp and Oracle EBS Payments were actively exploited. The SimpleHelp flaw allows attackers to gain unauthorized access to systems, posing a serious risk to users of the remote support software. Meanwhile, a vulnerability in Oracle's EBS Payments system has also come under attack, potentially compromising financial data for organizations using this enterprise resource planning software. These incidents emphasize the growing challenges in securing software, particularly as companies increasingly integrate AI features, which often introduce new vulnerabilities. Organizations relying on these systems need to prioritize patching and monitoring to protect sensitive information.
Nissan Americas has been impacted by a significant data breach linked to a zero-day vulnerability in Oracle’s PeopleSoft software, identified as CVE-2026-35273. This vulnerability has led to a series of attacks, with researchers connecting it to a group known as UNC6240, which is believed to be exploiting the weakness. The breach raises serious concerns about the security of sensitive employee information and operational data within Nissan Americas and potentially other organizations using the same software. As attackers continue to exploit this vulnerability, affected companies must act quickly to secure their systems and protect their data from further unauthorized access.
Security Affairs
A serious vulnerability, identified as CVE-2026-46817, has been discovered in Oracle E-Business Suite, allowing remote attackers to gain unauthorized access to Oracle Payments. This flaw has a high severity rating of 9.8 on the CVSS scale and is currently being exploited in real-world attacks, according to cybersecurity firm Defused Cyber. Organizations using Oracle E-Business Suite need to be particularly vigilant, as this vulnerability can lead to significant financial and operational risks. The situation is critical, and immediate action is necessary to protect sensitive payment information and other related data from unauthorized access. Users and administrators should prioritize addressing this vulnerability to mitigate potential breaches.
The Hacker News
A serious vulnerability affecting Oracle E-Business Suite, identified as CVE-2026-46817, is currently being exploited by attackers. This flaw, which has a CVSS score of 9.8, relates to improper privilege management and authentication issues in Oracle Payments. If exploited, this vulnerability could allow unauthorized users to take control of affected instances, posing a significant risk to organizations using the software. The situation calls for immediate attention, as the vulnerability is actively being targeted in the wild. Companies using Oracle E-Business Suite should prioritize addressing this flaw to protect their systems and data from potential breaches.