Internet-facing Oracle E-Business Suite is not a single-victim problem once attackers can enumerate the exposed servers. A critical flaw in EBS turns into a repeatable target set, so patching is only part of the picture when the front end is already public.
More than 900 Oracle E-Business Suite instances are exposed online, and attacks are already in progress against them. The affected surface includes Oracle Payments and Concurrent Processing components, with the reporting naming CVE-2026-46817 and CVE-2025-61882 as the critical flaws being abused.
The scale matters because it lets attackers scan, find, and keep probing the same ERP entry points across many organizations. That makes internet-facing EBS look less like a one-off compromise path and more like a bulk exploitation lane.