Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Oracle EBS gets a 3-day patch clock

1 min read
18:20UTC

CISA gave Oracle E-Business Suite a three-day federal patch deadline on 15 July for a privilege-management flaw on a platform with a Clop extortion history.

TechnologyAssessed
Key takeaway

Oracle E-Business Suite's three-day KEV deadline flags ransomware risk given its Clop exploitation history.

CISA flagged Oracle E-Business Suite flaw CVE-2026-46817, an improper privilege-management bug, as a Known Exploited Vulnerability (KEV) on 15 July and gave federal agencies three days to patch it. Oracle E-Business Suite is the company's enterprise resource-planning (ERP) software for finance, supply-chain and HR operations, deployed deep inside large organisations.

The platform carries a Clop mass-exploitation history, the extortion crew behind the 2023 MOVEit file-transfer campaign that breached hundreds of organisations. For a chief information security officer (CISO), a listing on a platform with that lineage reads as an early ransomware warning rather than a routine patch note.

The three-day window matches the compressed deadline CISA attached to the first-ever Splunk catalogue entry in June , a timeline it reserves for flaws it expects attackers to mass-exploit fast. Clop's method is to hit an enterprise flaw at scale before defenders finish patching, then extort the data it lifts, which is why a privilege bug on widely deployed ERP software carries weight beyond its CVE score.

Deep Analysis

In plain English

Oracle E-Business Suite is business software many large companies use to run their finance, supply chain and HR systems. On 15 July, CISA added a flaw in it, CVE-2026-46817, to its list of actively exploited vulnerabilities, giving US federal agencies just three days to fix it, one of the shortest deadlines CISA sets. The extortion crew Clop has targeted this kind of software before, most notably in its 2023 attack on MOVEit file-transfer software that hit thousands of organisations. The tight three-day deadline reflects how seriously CISA rates the risk of this specific flaw being exploited.

Deep Analysis
Root Causes

Oracle E-Business Suite's three-day federal deadline reflects the platform's top-tier placement under CISA's risk-tiered BOD 26-04, reserved for flaws assessed as both easily exploitable and high-impact given how deeply ERP software is wired into finance, supply chain and HR processes.

Privilege-management bugs in ERP platforms are structurally attractive to extortion crews like Clop because a single escalation from a low-privileged account can expose the exact financial and personal records that make double-extortion ransom demands credible.

Escalation

No threat actor has yet been publicly attributed to active exploitation of CVE-2026-46817 itself, so this is a precautionary top-tier deadline rather than confirmed follow-on activity by Clop.

What could happen next?
  • Risk

    Oracle E-Business Suite's three-day deadline places it in CISA's top urgency tier, indicating the agency assesses both easy exploitability and high potential impact given the platform's finance and HR data holdings.

  • Precedent

    Clop's documented history of exploiting enterprise back-office software, including the 2023 MOVEit campaign, makes Oracle EBS a plausible future target even without confirmed current exploitation.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

CISA· 24 Jul 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.