Over 900 Oracle E-Business Suite (EBS) instances are exposed online and actively being targeted via CVE-2026-46817, a critical CVSS 9.8 unauthenticated HTTP takeover vulnerability in the Oracle Payments File Transmission component. Oracle patched the flaw in its May 2026 Critical Security Patch Update, but threat intelligence firm Defused observed active exploitation on honeypots over the weekend, with no public PoC code existing. Shadowserver tracks roughly 950 exposed EBS instances with unknown patch status. This follows a broader pattern of Oracle product exploitation, including PeopleSoft zero-days abused by ShinyHunters and Clop ransomware gang attacks on EBS instances targeting universities and major organizations.
Table of contents
Related Articles:269 Impressions