Oracle E-Business Suite CVE-2026-46817 Actively Exploited in Wild
Critical privilege management flaw in Oracle Payments (CVE-2026-46817, CVSS 9.8) affecting versions 12.2.3–12.2.15 is under active exploitation despite no public PoC.
Attack Brief
TargetOracle E-Business Suite / Oracle PaymentsVectorImproper privilege management and authentication; unauthenticated network access via HTTPAttributionunattributed
Technical Details
CVE IDsCVE-2026-46817AffectedOracle E-Business Suite versions 12.2.3 through 12.2.15
Impact
Confirmed DamageComplete takeover of Oracle Payments instances
Mitigation
PatchesOracle Critical Security Patch Update (May 2026)
Context
Similar AttacksCVE-2025-61882 (Oracle EBS, CVSS 9.8) exploited by Cl0p ransomware operation starting August 2025; CVE-2026-35273 (Oracle PeopleSoft Suite, CVSS 9.8) exploited by ShinyHunters in June 2026
Source
https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.htmlby The Hacker Newson 2026-06-30T00:00:00Z2 sources