CVE Tools

Over 900 Oracle E-Business instances exposed to ongoing attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedOracle E-Business SuiteOracle Payments

Our summary

More than 900 Oracle E-Business Suite (EBS) instances are reportedly reachable online while attackers are actively targeting a critical issue, CVE-2026-46817, in the File Transmission component of Oracle Payments. The flaw can be abused by unauthenticated attackers with HTTP network access to take over vulnerable systems through low-complexity techniques, making exposure particularly risky for exposed deployments. Oracle has released fixes in its May 2026 Critical Security Patch Update, and defenders are urged to patch immediately as scanners such as Shadowserver continue to observe a large number of potentially vulnerable installations.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store