Vulnerabilities
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Cyber RTJune 30, 20263 min read

A critical security flaw, CVE-2026-46817, in Oracle E-Business Suite's Oracle Payments is actively exploited, allowing unauthenticated attackers to take over systems. The vulnerability affects versions 12.2.3 to 12.2.15 and was patched last month. Defused Cyber observed exploitation without public proof-of-concept code. Another flaw, CVE-2026-35273, impacted Nissan, exposing sensitive employee data. Organizations are urged to enhance incident response processes.
A critical security vulnerability in Oracle E-Business Suite, identified as CVE-2026-46817, has been actively exploited, according to cybersecurity firm Defused Cyber. This flaw, which has a high CVSS score of 9.8, involves improper privilege management and authentication issues in Oracle Payments, making it susceptible to unauthorized takeovers. The vulnerability allows attackers with network access via HTTP to compromise Oracle Payments, posing a significant risk to affected systems.
The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Oracle addressed this flaw in its recent Critical Security Patch Update. Despite the availability of patches, the vulnerability has been actively exploited, as evidenced by Defused Cyber's observations of exploitation attempts on their Oracle E-Business honeypots. Notably, there is no public proof-of-concept code available, and details about the exploitation methods and responsible parties remain unknown.
This security issue is part of a broader pattern of vulnerabilities in Oracle products being targeted by threat actors. Last year, a similar critical flaw, CVE-2025-61882, was exploited by the Cl0p ransomware group, highlighting the ongoing risks associated with unpatched Oracle systems. These incidents underscore the importance of timely patching and proactive security measures to mitigate potential threats.
In addition to the Oracle E-Business Suite vulnerability, another critical zero-day flaw in the PeopleSoft Suite, CVE-2026-35273, was recently addressed by Oracle. This vulnerability was actively exploited in data theft and extortion attacks by the ShinyHunters group. Notably, automaker Nissan was among the victims, with the breach potentially exposing sensitive employee data across multiple countries.
Security researcher Jake Knott from watchTowr emphasized the complexity of the PeopleSoft vulnerability, noting that it involves a sophisticated attack chain that combines multiple vulnerabilities. This suggests that the threat actors possess a deep understanding of the codebase and can develop targeted capabilities. Such advanced exploitation tactics highlight the evolving nature of cybersecurity threats.
Knott also highlighted the increasing speed at which threat actors are exploiting vulnerabilities, urging organizations to assume compromise and activate incident response processes. This proactive approach is essential to determine if access was gained before patches were applied, what data was accessed, and whether any persistent threats remain within the system.
The ongoing exploitation of these vulnerabilities serves as a reminder of the critical importance of cybersecurity vigilance. Organizations are encouraged to stay informed about potential threats and ensure that their systems are updated with the latest security patches. Following cybersecurity news and updates on platforms like Google News, Twitter, and LinkedIn can help organizations stay ahead of emerging threats and protect their digital assets.


