securityaffairs.com 6/30/2026, 9:33:09 AM · external

Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817

Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
Developing story malware 15 articles tracked
Active exploitation of Oracle E-Business Suite and PeopleSoft flaws (CVE-2026-46817, CVE-2026-35273)
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite has been actively exploited by attackers, allowing unauthenticated access to Oracle Payments systems. This flaw, with a CVSS score of 9.8, affects versions 12.2.3 to 12.2.15. Though Oracle has issued a patch, the flaw had no known prior exploitation or public proof-of-concept code available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is also monitoring related vulnerabilities. The issue underscores the importance of timely patching, especially in a landscape where zero-day exploits can affect large numbers of organizations.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline