Critical Oracle E-Business Suite Flaw Exploited for Unauthenticated Takeover
Attackers are actively exploiting CVE-2026-46817, a critical 9.8 severity flaw in the Oracle Payments File Transmission component of Oracle E-Business Suite. The vulnerability affects EBS versions 12.2.3 through 12.2.15 and allows unauthenticated attackers with HTTP access to compromise confidentiality, integrity, and availability on vulnerable systems. Oracle addressed the issue in its May 2026 Critical Patch Update and urged customers to apply fixes immediately.
Security researchers observed in-the-wild exploitation against Oracle EBS honeypots, including crafted POST requests to the /OA_HTML/ibytransmit endpoint with XML payloads abusing the CODEX_PULL transmission scheme. The activity reportedly attempted to read /etc/passwd, pointing to a local file read or path traversal exploitation chain, and occurred despite no known public proof-of-concept, suggesting private exploit tooling. Internet scanning data indicates more than 450 exposed Oracle EBS instances remain reachable, with attack activity recorded across multiple regions, including North America, Europe, and Asia.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Shadowserver tracks roughly 950 exposed Oracle EBS instances
BleepingComputer reported that Shadowserver was tracking roughly 950 internet-exposed Oracle E-Business Suite instances amid ongoing exploitation of CVE-2026-46817. The report said it was unclear how many of those exposed systems remained vulnerable to the flaw.
Shadowserver records 456 attack hits targeting exposed Oracle EBS
Shadowserver telemetry recorded 456 attack hits on June 28, 2026, targeting internet-exposed Oracle E-Business Suite instances across multiple regions, with North America and Asia leading. Separate reporting also noted more than 450 exposed Oracle EBS instances being tracked, though patch status was unclear.
Defused observes exploitation of Oracle EBS flaw on honeypots
Defused observed active exploitation of CVE-2026-46817 against Oracle E-Business Suite honeypots during June 27-28, 2026. The activity included targeted POST requests to the /OA_HTML/ibytransmit endpoint with crafted XML payloads abusing the CODEX_PULL transmission scheme and attempting to read /etc/passwd.
Oracle patches CVE-2026-46817 in Critical Patch Update
Oracle fixed CVE-2026-46817, a critical vulnerability in the Oracle Payments File Transmission component of Oracle E-Business Suite, in its May 2026 Critical Patch Update. One reference explicitly dates this patch release to May 28, 2026.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
11 references tracked. Mallory keeps watching after this page renders.
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
theregister.com
Open sourceOracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
securityaffairs.com
Open sourceResearchers spot exploitation of another critical Oracle defect | CyberScoop
cyberscoop.com
Open sourceOver 900 Oracle E-Business instances exposed to ongoing attacks
bleepingcomputer.com
Open sourceOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
thehackernews.com
Open sourceOracle E-Business Suite Payments flaw under attack (CVE-2026-46817) - Help Net Security
helpnetsecurity.com
Open sourceHackers Exploiting Critical Oracle E-Business Suite Vulnerability Actively in Attacks - Cyber Security News
cybersecuritynews.com
Open sourceHackers now exploit critical Oracle E-Business flaw in attacks
bleepingcomputer.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


