A critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite has been actively exploited by attackers, allowing unauthenticated access to Oracle Payments systems. This flaw, with a CVSS score of 9.8, affects versions 12.2.3 to 12.2.15. Though Oracle has issued a patch, the flaw had no known prior exploitation or public proof-of-concept code available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is also monitoring related vulnerabilities. The issue underscores the importance of timely patching, especially in a landscape where zero-day exploits can affect large numbers of organizations.
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
cybersixt.com
-
CISA alerts on active KNX flaw CVE‑2023‑4346, urges action
cybersixt.com
-
CISA flags Oracle E‑Business Suite flaw CVE‑2026‑46817 in KEV
cybersixt.com
-
CISA alerts on active KNX flaw CVE‑2023‑4346, urges action
cybersixt.com
-
CISA Adds CVE-2026-46817 to Known Exploited Vulnerabilities Catalogue
cybersixt.com
-
Oracle EBS flaw CVE-2026-46817 under attack, 950 systems exposed
cybersixt.com
-
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
cybersixt.com
-
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
securityaffairs.com
-
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
cybersixt.com