Hackers Actively Exploit Critical Oracle E-Business Suite Flaw
Attackers are actively exploiting CVE-2026-46817, a critical remote code execution vulnerability in Oracle E-Business Suite, posing a significant risk to financial operations.

Threat actors have begun actively exploiting a critical vulnerability, identified as CVE-2026-46817, within Oracle's E-Business Suite (EBS) financial application. This discovery comes from threat intelligence firm Defused, which has observed the flaw being leveraged in real-world attacks.
The vulnerability resides in the Oracle E-Business Suite, a widely used enterprise resource planning (ERP) software that manages critical business functions such as finance, human resources, and supply chain operations. The exploitation of this flaw allows attackers to achieve remote code execution (RCE), meaning they can run arbitrary commands on the affected systems without any prior authentication or user interaction.
This RCE capability presents a severe security risk to organizations relying on Oracle EBS for their core financial and operational data. Successful exploitation could lead to a complete compromise of the affected servers, enabling attackers to steal sensitive financial information, disrupt business processes, deploy ransomware, or use the compromised systems as a pivot point for further network intrusion.
The specific technical details of CVE-2026-46817 have not been fully disclosed by Oracle or researchers, but its classification as "critical" and its active exploitation indicate a high level of severity and immediate threat. Organizations using Oracle E-Business Suite are strongly advised to prioritize patching and implementing robust security measures to protect their environments.
Oracle typically releases security updates through its Critical Patch Update (CPU) program. While the exact patch for CVE-2026-46817 is not explicitly mentioned in this initial report, customers are urged to consult Oracle's official security advisories and apply the latest available patches as soon as possible. Proactive security practices, such as network segmentation, regular vulnerability scanning, and intrusion detection systems, can also help mitigate the risk.
The active exploitation of this Oracle EBS vulnerability underscores a persistent trend of attackers targeting widely used enterprise software. Organizations must remain vigilant, ensuring their critical business applications are up-to-date and adequately secured against emerging threats. The potential impact of such exploits on financial data and business continuity necessitates a swift and comprehensive response from affected entities.
This new report details the first confirmed instances of in-the-wild exploitation of CVE-2026-46817, observed over the weekend of June 27-28, 2026, on honeypot infrastructure. The exploitation involves crafted XML payloads targeting the File Transmission component via POST requests to the /OA_HTML/ibytransmit endpoint, with indicators suggesting path traversal techniques were used to read sensitive files like /etc/passwd. Shadowserver data indicates a significant number of hits, primarily in North America and Asia, highlighting the widespread risk to unpatched systems.
The vulnerability, CVE-2026-46817, is an improper privilege management and authentication flaw within Oracle Payments. While patches were released in Oracle's June Critical Security Patch Update, threat intelligence firm Defused Cyber observed active exploitation of the flaw on their honeypots over the weekend. Currently, details regarding the exploitation method, threat actors involved, or the scale of the attacks remain unknown.
The new article from SecurityWeek reports that threat actors have begun actively exploiting CVE-2026-46817 in Oracle E-Business Suite's Payments component. This exploitation was observed by Defused on their honeypots over the weekend, despite no previous public proof-of-concept exploits being available. The vulnerability, which allows unauthenticated attackers to achieve complete control over the affected component, was patched by Oracle in their late May Critical Security Patch Update.
New intelligence indicates that exploitation attempts targeting Oracle Payments, specifically CVE-2026-46817, are occurring in the wild. These attacks were detected approximately six weeks after Oracle released a patch for the vulnerability and notably, before any public proof-of-concept exploit was available, suggesting targeted and sophisticated campaigns.
While Oracle has yet to officially confirm exploitation in the wild, threat intelligence firm Defused reported observing active exploitation attempts over the weekend on their Oracle E-Business honeypots. This new intelligence indicates that the vulnerability, CVE-2026-46817, is no longer theoretical and is actively being leveraged by threat actors, despite the absence of publicly available proof-of-concept code.
Researchers at Defused have observed six exploitation attempts of CVE-2026-46817 on their honeypots, occurring before public proof-of-concept code was available. These early-stage attempts, attributed to a single IP address, suggest reconnaissance and weaponization testing rather than a full-scale campaign, though over 950 vulnerable instances of Oracle E-Business Suite have been identified globally.
This new report indicates that attackers were actively exploiting CVE-2026-46817 in Oracle E-Business Suite's Payments module even before public exploit code was released. Researchers observed targeted exploitation attempts on specific components, suggesting attackers either reverse-engineered the patch or had prior access to an exploit, rather than engaging in broad internet scanning.
New scanning data reveals that over 900 Oracle E-Business Suite instances are exposed online, significantly increasing their attack surface. Researchers have enhanced their fingerprinting methodology to identify these instances more accurately, with approximately 950 now tracked globally. This expanded visibility highlights the widespread potential impact of the actively exploited CVE-2026-46817 vulnerability.