securityaffairs.com 30 Jun 2026, 09:01 UTC

Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817

Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite has been actively exploited by attackers, allowing unauthenticated access to Oracle Payments systems. This flaw, with a CVSS score of 9.8, affects versions 12.2.3 to 12.2.15. Though Oracle has issued a patch, the flaw had no known prior exploitation or public proof-of-concept code available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is also monitoring related vulnerabilities. The issue underscores the importance of timely patching, especially in a landscape where zero-day exploits can affect large numbers of organizations.

View Primary Source Via securityaffairs.com

Article by CyberSIXT