CVE-2026-46817
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 0.8% (55º percentile).
Data di correzione federale CISA 18 lug
Vulnerabilità · 81 giorni fa
Il punto non è il singolo file letto. In Oracle Payments, un accesso non autenticato al percorso giusto può aprire anche configurazioni, credenziali di database, chiavi di cifratura e API key dei pagamenti: un bug nato come file-read diventa un ponte verso il resto dello stack finanziario.
Defused ha osservato il 27 giugno il primo sfruttamento in the wild di CVE-2026-46817 sui propri honeypot Oracle E-Business Suite, circa sei settimane dopo la patch di maggio di Oracle e prima di qualsiasi public PoC. L’attività era a sorgente singola e mirata, non una scansione indiscriminata; il difetto riguarda Oracle E-Business Suite 12.2.3 through 12.2.15 ed espone il componente File Transmission di Oracle Payments.
Per chi espone EBS su Internet, il rischio non si ferma alla web tier: un’istanza non patchata può aver già riversato segreti riutilizzabili altrove, anche se il file richiesto sembra banale.
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 0.8% (55º percentile).
Data di correzione federale CISA 18 lug
7 fonti che coprono questa storia
Attackers appear to have reverse-engineered Big Red's patch
Researchers spot exploitation of another critical Oracle defect
The defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees.
Critical flaw in Oracle E-Business Suite is under immediate threat
Researchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments.
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) - Help Net Security
Exploitation attempts targeting a vulnerability (CVE-2026-46817) in Oracle's E-Business Suite's Oracle Payments module have been spotted.
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product.
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Oracle E-Business Suite vulnerability CVE-2026-46817 (CVSS 9.8) is being actively exploited in the wild despite Oracle’s recent patch release.
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
The ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization.
Insurance body confirms hackers posted Oracle PeopleSoft breach data
NAIC warned that some ratings agencies have suspended data feeds as a precaution.
Hackers now exploit critical Oracle E-Business flaw in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused.
Part of the PlainSec briefing for 2026-07-01