<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr" -->

---
title: Over 900 Oracle E-Business instances exposed to ongoing...
description: Over 900 Oracle E-Business Suite (EBS) instances are exposed online and actively being targeted via CVE-2026-46817, a critical CVSS 9.8 unauthenticated HTTP...
canonical: https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Over 900 Oracle E-Business instances exposed to ongoing attacks | daily.dev
og:description: Over 900 Oracle E-Business Suite (EBS) instances are exposed online and actively being targeted via CVE-2026-46817, a critical CVSS 9.8 unauthenticated HTTP...
og:url: https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr
og:image: https://api.daily.dev/og/posts/Fl9aO0jnr.png
og:image:alt: Over 900 Oracle E-Business instances exposed to ongoing attacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Over 900 Oracle E-Business instances exposed to ongoing attacks

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Over 900 Oracle E-Business Suite (EBS) instances are exposed online and actively being targeted via CVE-2026-46817, a critical CVSS 9.8 unauthenticated HTTP takeover vulnerability in the Oracle Payments File Transmission component. Oracle patched the flaw in its May 2026 Critical Security Patch Update, but threat intelligence firm Defused observed active exploitation on honeypots over the weekend, with no public PoC code existing. Shadowserver tracks roughly 950 exposed EBS instances with unknown patch status. This follows a broader pattern of Oracle product exploitation, including PeopleSoft zero-days abused by ShinyHunters and Clop ransomware gang attacks on EBS instances targeting universities and major organizations.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks>

## Similar posts on daily.dev

- [Hackers now exploit critical Oracle E-Business flaw in attacks](https://daily.dev/posts/hackers-now-exploit-critical-oracle-e-business-flaw-in-attacks-1agfs2mks) · BleepingComputer · 0 upvotes · 0 comments
- [CISA orders feds to patch actively exploited Oracle flaw by Saturday](https://daily.dev/posts/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday-kdqwicqci) · BleepingComputer · 1 upvotes · 0 comments
- [Oracle warns of security bug that hackers abused to breach 100\+ companies](https://daily.dev/posts/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies-vgnqoxr03) · TechCrunch · 0 upvotes · 0 comments
- [Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released](https://daily.dev/posts/oracle-e-business-suite-was-under-attack-via-critical-flaw-before-the-public-exploit-code-was-even-r-a4zmoqx0g) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability), [#oracle](https://daily.dev/tags/oracle)

[View this post on daily.dev](https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Over 900 Oracle E-Business instances exposed to ongoing attacks","url":"https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr"},"datePublished":"2026-07-01T12:34:18.273Z","dateModified":"2026-07-01T12:34:41.984Z","description":"Over 900 Oracle E-Business Suite (EBS) instances are exposed online and actively being targeted via CVE-2026-46817, a critical CVSS 9.8 unauthenticated HTTP...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4ac61fe40f337465f7b7a80f7267b0d5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4ac61fe40f337465f7b7a80f7267b0d5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks-fl9ao0jnr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,vulnerability,oracle","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Over 900 Oracle E-Business instances exposed to ongoing attacks"}]}
```

