Attackers begin exploiting Oracle E-Business Suite Payments flaw CVE-2026-46817

Attackers have started probing and exploiting a critical Oracle E-Business Suite bug that can let outsiders take over the Payments component without logging in. The flaw, CVE-2026-46817, affects the File Transmissions component in Oracle E-Business Suite Payments and can be exploited over HTTP by an unauthenticated attacker. Oracle patched it in late May 2026 in its first monthly Critical Security Patch Update, and Defused says it saw the first exploitation attempts hit EBS honeypots over the weekend.
Why it matters: Organizations running Oracle E-Business Suite Payments now face real attack activity, not just a theoretical flaw. This is patch-now territory for internet-exposed systems, especially where payment workflows are involved.

Sources

CISA orders feds to patch actively exploited Oracle flaw by Saturday
Sergiu Gatlan 2026.07.16 96% relevant
This advances the same underlying event by adding CISA’s confirmation of in-the-wild exploitation, KEV inclusion, and a federal patch deadline of July 18 under BOD 26-04 for Oracle E-Business Suite Oracle Payments CVE-2026-46817.
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
2026.07.02 97% relevant
This article directly updates the same event by adding that exploitation of CVE-2026-46817 was observed on June 27 before any public proof-of-concept was released, likely via patch reverse-engineering, with targeted attempts against the Oracle Payments File Transmission component in E-Business Suite 12.2.3 through 12.2.15.
Over 900 Oracle E-Business instances exposed to ongoing attacks
Sergiu Gatlan 2026.07.01 96% relevant
This directly updates the same event by adding exposure scope and urgency: Shadowserver tracks about 950 internet-exposed Oracle E-Business Suite instances, BleepingComputer reports over 900 exposed systems amid ongoing exploitation, and the attacks target the same Oracle Payments File Transmission flaw, CVE-2026-46817.
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
Ionut Arghire 2026.06.30 100% relevant
The article establishes a distinct story because it moves CVE-2026-46817 from a patched vulnerability to one being actively exploited in the wild, with concrete observations from honeypots.
← Back to all stories