Vulnerabilities · 75 days ago

Exposed Oracle EBS Servers Become a Mass Target

Internet-facing Oracle E-Business Suite is not a single-victim problem once attackers can enumerate the exposed servers. A critical flaw in EBS turns into a repeatable target set, so patching is only part of the picture when the front end is already public.

More than 900 Oracle E-Business Suite instances are exposed online, and attacks are already in progress against them. The affected surface includes Oracle Payments and Concurrent Processing components, with the reporting naming CVE-2026-46817 and CVE-2025-61882 as the critical flaws being abused.

The scale matters because it lets attackers scan, find, and keep probing the same ERP entry points across many organizations. That makes internet-facing EBS look less like a one-off compromise path and more like a bulk exploitation lane.

CVE-2025-61882

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Oct 27 · date passed

CVE-2026-46817

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 13% (96th percentile).

CISA federal remediation date Jul 18

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-07-02

Editions

Related stories