CVE-2026-46817
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 0.8% (55º percentile).
Data di correzione federale CISA 18 lug
Vulnerabilità ed exploit
Il punto non è il singolo file letto. In Oracle Payments, un accesso non autenticato al percorso giusto può aprire anche configurazioni, credenziali di database, chiavi di cifratura e API key dei pagamenti: un bug nato come file-read diventa un ponte verso il resto dello stack finanziario.
Defused ha osservato il 27 giugno il primo sfruttamento in the wild di CVE-2026-46817 sui propri honeypot Oracle E-Business Suite, circa sei settimane dopo la patch di maggio di Oracle e prima di qualsiasi public PoC. L’attività era a sorgente singola e mirata, non una scansione indiscriminata; il difetto riguarda Oracle E-Business Suite 12.2.3 through 12.2.15 ed espone il componente File Transmission di Oracle Payments.
Per chi espone EBS su Internet, il rischio non si ferma alla web tier: un’istanza non patchata può aver già riversato segreti riutilizzabili altrove, anche se il file richiesto sembra banale.
7 fonti · 10 lug
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 0.8% (55º percentile).
Data di correzione federale CISA 18 lug
The Register Security
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Attackers appear to have reverse-engineered Big Red's patch
originaleCyberScoop
Researchers spot exploitation of another critical Oracle defect
The defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees.
originaleCybersecurity Dive
Critical flaw in Oracle E-Business Suite is under immediate threat
Researchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments.
originalePart of the PlainSec briefing for 2026-07-01
Every edition of this story: Oracle Payments trasforma un file-read in furto di segreti