Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)
Vulnerability
Summary
Hide ▲
Show ▼
Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP access to compromise vulnerable systems through a low-complexity attack path. Defused Cyber observed exploitation on Oracle E-Business honeypots over the weekend, and Oracle says it addressed the issue in the May 2026 Critical Security Patch Update. Exposed Oracle EBS instances remain at risk until patched.
Related Happenings
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation Wave
H score82
First: 29.06.2026 13:00
Last: 29.06.2026 13:00
Sources 1
About this happening:
A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Oracle PeopleSoft broad zero-day exploitation campaign
Exploitation WaveAbout this happening: A broad PeopleSoft zero-day exploitation campaign exposed multiple organizations to compromise after attackers abused a previously unknown Oracle PeopleSoft vulnerabilit...
Oracle WebLogic Server unauthenticated remote compromise flaw (CVE-2024-21182)
Vulnerability
H score59
First: 02.06.2026 15:40
Last: 02.06.2026 15:40
Sources 1
About this happening:
CVE-2024-21182 in Oracle WebLogic Server is actively exploited and can let a network-access attacker achieve unauthenticated remote compromise. The flaw affect...
Oracle WebLogic Server unauthenticated remote compromise flaw (CVE-2024-21182)
VulnerabilityAbout this happening: CVE-2024-21182 in Oracle WebLogic Server is actively exploited and can let a network-access attacker achieve unauthenticated remote compromise. The flaw affect...
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector Action
H score53
First: 02.06.2026 15:40
Last: 02.06.2026 15:40
Sources 1
About this happening:
CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
Initial-access handoff time drops to 22 seconds across Mandiant investigations
Trend
H score26
First: 23.03.2026 17:00
Last: 23.03.2026 17:00
Sources 1
About this happening:
Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...
Initial-access handoff time drops to 22 seconds across Mandiant investigations
TrendAbout this happening: Across Mandiant investigations, the time from initial access to handoff to a secondary threat group has collapsed to 22 seconds, sharply reducing defenders’ window...
Rising encryptionless extortion incidents against enterprises in 2025
Trend
H score27
First: 15.01.2026 17:45
Last: 15.01.2026 17:45
Sources 1
About this happening:
Encryptionless extortion surged in 2025 as attackers increasingly skipped ransomware encryption and instead stole data to pressure victims across enterprise environments...
Rising encryptionless extortion incidents against enterprises in 2025
TrendAbout this happening: Encryptionless extortion surged in 2025 as attackers increasingly skipped ransomware encryption and instead stole data to pressure victims across enterprise environments...
Timeline
-
29.06.2026 16:46 3 articles · 16d ago
Defused says attackers are exploiting Oracle E-Business Suite CVE-2026-46817
Initial DisclosureDefused said attackers are actively exploiting CVE-2026-46817 in Oracle E-Business Suite, with the first attempts observed over the weekend against the File Transmission component in Oracle Payments. The flaw allows unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks, and Oracle says it addressed the issue in the May 2026 Critical Security Patch Update and urged customers to patch immediately. Shadowserver also reported more than 450 Oracle EBS instances exposed online, including nearly 200 in the United States and Europe, while no public proof-of-concept code is known.
Show sources
- Hackers now exploit critical Oracle E-Business flaw in attacks — www.bleepingcomputer.com — 29.06.2026 16:46
- Hackers now exploit critical Oracle E-Business flaw in attacks — www.bleepingcomputer.com — 29.06.2026 16:46
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild — thehackernews.com — 30.06.2026 08:04