Over 900 Oracle E-Business instances exposed to ongoing attacks
Reported exploitedOracle E-Business SuiteOracle PaymentsOur summary
More than 900 Oracle E-Business Suite (EBS) instances are reportedly reachable online while attackers are actively targeting a critical issue, CVE-2026-46817, in the File Transmission component of Oracle Payments. The flaw can be abused by unauthenticated attackers with HTTP network access to take over vulnerable systems through low-complexity techniques, making exposure particularly risky for exposed deployments. Oracle has released fixes in its May 2026 Critical Security Patch Update, and defenders are urged to patch immediately as scanners such as Shadowserver continue to observe a large number of potentially vulnerable installations.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.