www.securityweek.com 6/30/2026, 12:02:20 PM · external

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
Developing story malware 16 articles tracked
Active exploitation of Oracle E-Business Suite and PeopleSoft flaws (CVE-2026-46817, CVE-2026-35273)
CyberSIXT Evidence Panel
Primary Source oracle.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical vulnerability in Oracle E-Business Suite (EBS), tracked as CVE-2026-46817 with a CVSS score of 9.8, is being actively exploited by threat actors. The flaw allows unauthenticated HTTP access that could lead to takeover of the Oracle Payments component. Oracle has released patches for this vulnerability as part of its May Critical Security Patch Update addressing 77 vulnerabilities total. Threat intelligence firm Defused reported recent exploitation attempts against the flaw in their EBS honeypots.

Organizations are advised to apply Oracle's patches immediately due to the critical nature of the vulnerability, especially given past incidents involving Oracle products being targeted by groups such as Cl0p and ShinyHunters.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline