CVE Tools

Hackers now exploit critical Oracle E-Business flaw in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedOracle E-Business Suite

Our summary

Threat actors are actively exploiting a critical issue in Oracle E-Business Suite (EBS) that tracks as CVE-2026-46817. The weakness affects the File Transmission component within Oracle Payments and allows unauthenticated attackers with HTTP network access to take over vulnerable systems. Oracle has released fixes in its May 2026 Critical Security Patch Update, and the public exploitation increase makes prompt patching especially important for exposed EBS instances.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store