CVE-2026-46817
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 13% (96th percentile).
CISA federal remediation date Jul 18
Vulnerabilities · 66 days ago
Oracle Payments is exposed to more than a file leak here. A single unauthenticated request can make Oracle’s own code read server files, so an attacker who reaches the Payments file-transmission path may walk away with configuration data, database credentials, encryption keys, or payment API keys.
Defused says it saw the first in-the-wild exploitation of CVE-2026-46817 on 27 June, about six weeks after Oracle’s May patch and before any public proof of concept. The activity was single-source and targeted, not broad scanning, and it hit Oracle E-Business Suite Payments honeypots running versions 12.2.3 through 12.2.15.
The risk is bigger than the bug itself. If an internet-facing EBS Payments instance was left unpatched, the problem may already have moved past the web tier into the secrets that let attackers reach databases and payment integrations.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 13% (96th percentile).
CISA federal remediation date Jul 18
7 sources covering this story
Attackers appear to have reverse-engineered Big Red's patch
Researchers spot exploitation of another critical Oracle defect
The defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees.
Critical flaw in Oracle E-Business Suite is under immediate threat
Researchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments.
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) - Help Net Security
Exploitation attempts targeting a vulnerability (CVE-2026-46817) in Oracle's E-Business Suite's Oracle Payments module have been spotted.
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product.
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Oracle E-Business Suite vulnerability CVE-2026-46817 (CVSS 9.8) is being actively exploited in the wild despite Oracle’s recent patch release.
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
The ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization.
Insurance body confirms hackers posted Oracle PeopleSoft breach data
NAIC warned that some ratings agencies have suspended data feeds as a precaution.
Hackers now exploit critical Oracle E-Business flaw in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused.
Part of the PlainSec briefing for 2026-07-01