Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-46817 | Unauthenticated Takeover of Oracle Payments in Oracle E-Business Suite (CVE-2026-46817) Oracle E-Business Suite contains a critical improper privilege management flaw (CVE-2026-46817) in the File Transmission component of Oracle Payments, affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger it, with no credentials or user interaction required. Successful exploitation results in takeover of Oracle Payments, with high confidentiality, integrity, and availability impact (CVSS 3.1 9.8). Organizations running the affected E-Business Suite releases — especially those exposing the Payments/File Transmission interface to untrusted networks — are in scope. The issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-15, researchers have observed exploitation in the wild, and EPSS assigns a 13% probability of exploitation within 30 days (96th percentile). Do: Apply the remediation provided in Oracle's security advisory for CVE-2026-46817 to all Oracle E-Business Suite 12.2.3–12.2.15 environments running Oracle Payments, and in the meantime restrict HTTP/network access to the File Transmission component. Because the flaw is being actively exploited, review EBS/Payments access logs for unauthenticated requests and anomalous file-transmission activity to check for compromise. Federal agencies must apply mitigations in line with CISA BOD 26-04 timelines or discontinue use of the product if mitigations are unavailable. | 9.8 | 13% | KEV |
| moderate≈ several thousand installations (roughly 1k–10k Oracle EBS environments running Oracle Payments, with only a subset internet-reachable) |
Full article373 words · extracted from securityaffairs.com · click to collapse

Oracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed.
This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited. The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP. Oracle fixed the issue in last month’s Critical Patch Update and urges customers to apply the patches immediately.
Defused Cyber did not disclose technical details about the attacks that exploited the flaw or the motivation of the attackers.
— Defused (@DefusedCyber) June 29, 2026🚨 CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited
Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots
This vulnerability has no known previous exploitation and no public POC code… pic.twitter.com/qL4dgPvoMP
Now, Internet monitoring firm Shadowserver counts roughly 950 EBS instances still reachable from the public internet, most of them in the United States. Nobody knows how many of those have been patched.
“We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with @ValidinLLC. Around 950 exposed instances now seen globally (no vulnerability assessment).” reads the post published by The Shadowserver Foundation.
We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with @ValidinLLC. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by @DefusedCyber pic.twitter.com/gghdTt5b1X
— The Shadowserver Foundation (@Shadowserver) July 1, 2026
Despite researchers confirming active exploitation of the vulnerabilities, Oracle hasn’t officially flagged this vulnerability as exploited in the wild.
If your organization runs Oracle EBS and hasn’t applied it, that’s the immediate priority. If a public-facing EBS instance is genuinely required for business operations, verify it’s patched before checking anything else on your list today. If it doesn’t need to be internet-facing, take it off the internet.
Shadowserver’s scan suggests the exposed population is not small, and active exploitation without a public proof-of-concept means the attacker community is already ahead of most defenders on this one.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Oracle E-Business)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/194599/security/oracle-e-business-suite-flaw-under-active-attack-950-systems-exposed.html