Oracle E-Business Suite Flaw CVE-2026-46817 Exploited In The Wild, 950 Instances Exposed

Attackers are exploiting a critical unauthenticated flaw in Oracle E-Business Suite Payments in the wild, and Shadowserver counts roughly 950 vulnerable instances still reachable from the public internet.

Oracle E-Business Suite Flaw CVE-2026-46817 Exploited In The Wild, 950 Instances Exposed

A critical unauthenticated remote code execution flaw in Oracle E-Business Suite is being exploited in the wild before any public proof-of-concept code has appeared, and Internet monitor Shadowserver counts roughly 950 vulnerable instances still reachable from the open internet — most of them in the United States.

CVE-2026-46817: HTTP Takeover Of Oracle Payments

Tracked as CVE-2026-46817 and carrying a CVSS score of 9.8, the vulnerability sits in Oracle Payments versions 12.2.3 through 12.2.15 and lets an unauthenticated attacker take over vulnerable systems over plain HTTP. Oracle shipped the fix in its May 2026 Critical Patch Update but did not initially flag the bug as exploited. That changed at the end of June when threat researchers at Defused Cyber said they had observed an actor exploiting the vulnerability on their Oracle EBS honeypots, and disclosed the activity via social media on June 29, 2026.

Shadowserver: ~950 Exposed Instances Globally

Following the honeypot disclosure, The Shadowserver Foundation improved its EBS fingerprinting in collaboration with Validin and now tracks approximately 950 exposed instances worldwide — the volumetric baseline defenders should assume attackers are already probing. Shadowserver does not perform vulnerability assessment on those hosts, so it is unclear how many have been patched, but active exploitation without public exploit code means the attacker community is well ahead of most defenders.

Data center servers cyber security

What Defenders Should Do Right Now

Security teams running Oracle EBS should treat CVE-2026-46817 as an immediate patch-or-remove decision. If the instance genuinely needs to be reachable from the public internet for business operations, verify May 2026 CPU patches are in place before touching anything else. If it does not need to be internet-facing, take it off the internet. The larger picture — legacy on-premises ERP running unauthenticated services on port 80 — is exactly the profile attackers hunt for as they pivot from SaaS supply-chain intrusions to unpatched enterprise back offices.

Related coverage: Broadcom patches VMware vCenter and ESXi auth-bypass and VM escape flaws, JetBrains patches critical TeamCity RCE CVE-2026-63077, and Microsoft unveils MAI-Cyber-1 Flash and Project Perception.

Reporting based on coverage from Security Affairs, GBHackers, BleepingComputer and Defused Cyber.

Category: Cyber Security

Tags: AI Cybersecurity Industrial AI Patch Tuesday

Related Articles