Particle.news
Download on the App Store

Researchers Report Active Exploitation of Critical Oracle E‑Business Flaw

The move from patched advisory to in‑the‑wild attacks raises urgent risk for internet‑facing, unpatched Oracle E‑Business Suite systems.

Overview

  • Security firm Defused observed attackers exploiting CVE-2026-46817 against its Oracle E‑Business honeypots over the weekend, marking the first reported in‑the‑wild activity for the flaw.
  • Oracle published fixes for the vulnerability in its May 2026 Critical Patch Update, but the flaw remains dangerous because it lets an unauthenticated HTTP actor take over Oracle Payments on affected EBS versions.
  • The weakness carries a CVSS score of 9.8 and affects Oracle E‑Business Suite versions 12.2.3 through 12.2.15, meaning unpatched instances can be fully compromised without valid credentials.
  • Internet watchdog Shadowserver is tracking more than 450 Oracle EBS instances exposed online, many in the United States and Europe, which increases the pool of systems that attackers could target next.
  • There is no public proof‑of‑concept code or confirmed attacker attribution yet, but past weaponization of Oracle EBS flaws by ransomware gangs shows successful exploitation can lead to data theft and extortion.