Tag: improper privilege management
2 articles

CISA Warns of Active ScreenConnect Exploit in Ongoing Attacks
Beware: hackers are actively exploiting a critical flaw in ConnectWise ScreenConnect, allowing them to transfer files and execute code on vulnerable systems without permission. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning, ordering federal agencies to secure affected systems within three days.

Oracle E-Business Suite Flaw CVE-2026-46817 Sees Active Exploitation
A critical flaw in Oracle Payments, known as CVE-2026-46817, is being actively exploited by hackers, allowing them to easily take control of vulnerable Oracle E-Business Suite instances. This easily exploitable vulnerability has a near-perfect CVSS score of 9.8, making it a high-risk threat to organizations using Oracle Payments.