HomeSecurityOracle E-Business Suite: Vulnerability used in attacks

Oracle E-Business Suite: Vulnerability used in attacks

A critical security vulnerability in Oracle E-Business Suite (EBS) has raised alarm in the cybersecurity community, as experts confirm that cybercriminals have already begun actively exploiting it. The vulnerability, designated CVE-2026-46817, is considered particularly dangerous, as it could allow a remote attacker to gain complete control of a vulnerable system without requiring prior access or sophisticated techniques.

Oracle E-Business Suite

This development serves as a reminder that business applications are now one of the most important targets of modern cyberattacks, especially when they are used by large organizations to manage financial data and critical business processes.

What does the new vulnerability involve?

The vulnerability is located in the File Transmission of Oracle Payments, which is part of the Oracle E-Business Suite platform. According to security researchers, an attacker with HTTP access to the corporate network could exploit the vulnerability and take control of the system with relatively little technical difficulty.

See also: DirtyClone – pedit COW: New Linux vulnerabilities for privilege escalation

The severity of the vulnerability is reflected in the CVSS score of 9.8, one of the highest that can be assigned to a security flaw. Simply put, this is an error that can lead to a complete breach of corporate infrastructureif the necessary security updates have not been applied.

The first attacks are already underway

Although Oracle had released a patch via the May 2026 Critical Patch Update, analysts at threat intelligence firm Defused revealed that the vulnerability is already being used in real-world attacks.

Oracle E-Business Suite: Vulnerability used in attacks

The first attempts at exploitation were recorded in special honeypots used to monitor malicious activity on the Internet. What is particularly worrying is that no public exploit code (Proof of Concept) has been published so far, which suggests that the attacks are being carried out by groups with significant technical capabilities.

This increases the risk of further propagation of the attack, as it is common for tools to appear after the first successful exploits that allow even less experienced attackers to carry out similar attacks.

Hundreds of exposed systems

The Shadowserver internet monitoring group has already identified more than 450 publicly accessible Oracle E-Business Suite installations around the world, with about 200 of them located in the United States and Europe.

See also: New Miasma campaign targets npm packages and GitHub Actions

However, it remains unknown how many of these organizations have already installed the available security patches. This leaves open the possibility that many businesses are still vulnerable, especially those that delay updates due to demanding procedures or fear of disrupting critical services.

Oracle is a constant target of cybercriminals

This is not the first time that Oracle products have been targeted by organized hacking groups. In recent years, there have been several serious attacks that exploited vulnerabilities in the company's popular business applications.

Oracle E-Business Suite: Vulnerability used in attacks

The Clop group , which exploited an earlier vulnerability in Oracle E-Business Suite to attack universities, large enterprises, and organizations in the United States, was a notable example. Recent attacks have targeted both Oracle WebLogic Server and PeopleSoft Suite , demonstrating that enterprise management platforms are a particularly attractive target for ransomware and espionage groups.

Why business applications are a valuable target

Unlike a simple corporate computer, an Oracle EBS installation manages financials, customer data, personnel information, invoices, payments, and critical business functions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A successful breach can allow the theft of sensitive data, the alteration of financial transactions, or even the shutdown of an entire organization. In many cases, cybercriminals exploit such attacks for extortion via ransomware or for long-term persistence in corporate networks for the purpose of industrial espionage.

What should organizations do?

Cybersecurity experts recommend that businesses immediately install all available Oracle security updates and confirm that they are using supported versions of the software.

See also: PTC Windchill: Vulnerability exploited for the first time – CISA KEV

At the same time, it is important to restrict public access to Oracle EBS services, implement multi-factor authentication (MFA) mechanisms, continuously monitor logs for suspicious activity, and perform regular security audits.

The CVE-2026-46817 case is yet another reminder that delaying the installation of updates can prove to be very costly. In an environment where cyberattacks evolve daily, timely application of patches remains one of the most effective means of protection against modern digital threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS