Hackers now exploit critical Oracle E Business flaw in attacks
Attackers have started exploiting a critical flaw in Oracle E-Business Suite financial systems.
CVE-2026-46817 sits in the File Transmission component of Oracle Payments. Unauthenticated attackers reach it over HTTP and take over the service. CVSS 9.8, actively exploited per Defused honeypot data.
Affects EBS versions 12.2.3 through 12.2.15. Shadowserver sees over 450 instances exposed online, many in the US and Europe.
First exploitation attempts appeared over the weekend with no prior public PoC reported.
