CVE Tools

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

SecurityWeekBy Ionut Arghire

Reported exploitedOracle E-Business SuiteOracle Payments

Our summary

Threat actors have begun targeting a critical Oracle E-Business Suite (EBS) vulnerability tracked as CVE-2026-46817 (CVSS 9.8), with activity observed against the File Transmissions component in the Payments product. Oracle says unauthenticated attackers can exploit the issue over HTTP to take over Oracle Payments, making it a high-impact risk for organizations running EBS. The flaw was addressed in Oracle’s first monthly Critical Security Patch Update (CSPU) in late May, so defenders should prioritize patching to reduce exposure.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store