Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch Release
Summary
Hide ▲
Show ▼
Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an unauthenticated attacker via HTTP take over susceptible instances. Oracle had already shipped patches for versions 12.2.3 through 12.2.15 as part of the update, and Defused Cyber later reported active exploitation in the wild against honeypots.
Related Happenings
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation Wave
H score82
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
About this happening:
A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation WaveAbout this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector Action
H score53
First: 02.06.2026 15:40
Last: 02.06.2026 15:40
Sources 1
About this happening:
CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
Initial-access handoff time drops to 22 seconds across Mandiant investigations
Trend
H score26
First: 23.03.2026 17:00
Last: 23.03.2026 17:00
Sources 1
About this happening:
Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...
Initial-access handoff time drops to 22 seconds across Mandiant investigations
TrendAbout this happening: Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...
Oracle security patch release for CVE-2026-21992
Security Patch Release
H score44
First: 21.03.2026 12:24
Last: 21.03.2026 12:24
Sources 1
About this happening:
Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Oracle security patch release for CVE-2026-21992
Security Patch ReleaseAbout this happening: Oracle released security updates for CVE-2026-21992, a critical flaw in Identity Manager and Web Services Manager that could enable unauthenticated remote co...
Barts Health NHS Trust invoice leak on Cl0p leak portal
Data Leak
H score38
First: 05.12.2025 20:55
Last: 05.12.2025 20:55
Sources 1
About this happening:
The Barts Health NHS Trust data leak became public when Cl0p posted stolen invoice files on its dark-web leak portal, exposing full names and addresses linked...
Barts Health NHS Trust invoice leak on Cl0p leak portal
Data LeakAbout this happening: The Barts Health NHS Trust data leak became public when Cl0p posted stolen invoice files on its dark-web leak portal, exposing full names and addresses linked...
Latest development: 08.12.2025 11:30
Barts Health NHS Trust is seeking a High Court order to stop the sharing, publication or use of invoice files stolen from its Oracle E-business Suite (EBS) database; the trust says Cl0p posted the files on the dark web, and it is working with NHS England, the National Cyber Security Centre, the Metropolitan Police and regulators including the Information Commissioner’s Office while its clinical systems remain unaffected.
Timeline
-
29.06.2026 16:46 3 articles · 16d ago
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Initial DisclosureOracle issued the May 2026 Critical Security Patch Update for CVE-2026-46817 in Oracle E-Business Suite, directing customers to patch immediately after the flaw was identified as a takeover risk.
Show sources
- Hackers now exploit critical Oracle E-Business flaw in attacks — www.bleepingcomputer.com — 29.06.2026 16:46
- Hackers now exploit critical Oracle E-Business flaw in attacks — www.bleepingcomputer.com — 29.06.2026 16:46
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild — thehackernews.com — 30.06.2026 08:04