Attackers have started probing and exploiting a critical Oracle E-Business Suite bug that can let outsiders take over the Payments component without logging in. The flaw, CVE-2026-46817, affects the File Transmissions component in Oracle E-Business Suite Payments and can be exploited over HTTP by an unauthenticated attacker. Oracle patched it in late May 2026 in its first monthly Critical Security Patch Update, and Defused says it saw the first exploitation attempts hit EBS honeypots over the weekend.
Why it matters: Organizations running Oracle E-Business Suite Payments now face real attack activity, not just a theoretical flaw. This is patch-now territory for internet-exposed systems, especially where payment workflows are involved.
Sergiu Gatlan
2026.07.16
96% relevant
This advances the same underlying event by adding CISA’s confirmation of in-the-wild exploitation, KEV inclusion, and a federal patch deadline of July 18 under BOD 26-04 for Oracle E-Business Suite Oracle Payments CVE-2026-46817.
2026.07.02
97% relevant
This article directly updates the same event by adding that exploitation of CVE-2026-46817 was observed on June 27 before any public proof-of-concept was released, likely via patch reverse-engineering, with targeted attempts against the Oracle Payments File Transmission component in E-Business Suite 12.2.3 through 12.2.15.
Sergiu Gatlan
2026.07.01
96% relevant
This directly updates the same event by adding exposure scope and urgency: Shadowserver tracks about 950 internet-exposed Oracle E-Business Suite instances, BleepingComputer reports over 900 exposed systems amid ongoing exploitation, and the attacks target the same Oracle Payments File Transmission flaw, CVE-2026-46817.
Ionut Arghire
2026.06.30
100% relevant
The article establishes a distinct story because it moves CVE-2026-46817 from a patched vulnerability to one being actively exploited in the wild, with concrete observations from honeypots.
← Back to all stories