CVE Tools

Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Help Net SecurityBy Help Net Security

Advisory

Our summary

Attackers are actively exploiting CVE-2026-48558 in SimpleHelp RMM, using the authentication-bypass weakness to deploy the Djinn Stealer malware across Windows, macOS, and Linux systems. In parallel, threat intelligence reports exploitation attempts against CVE-2026-46817 affecting Oracle E-Business Suite Payments, with the Oracle Payments module targeted via weekend activity. These incidents matter because they show how quickly patched (or still-fresh) enterprise flaws can be weaponized, increasing the urgency of remediation and monitoring for both vendors.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store