loader image
Oracle E-Business Flaw Under Attack, 950 Exposed

A critical vulnerability in Oracle E-Business Suite, identified as CVE-2026-46817, is currently under active attack, with approximately 950 systems exposed. Defused Cyber researchers reported that this flaw, affecting Oracle Payments versions 12.2.3 through 12.2.15, allows attackers to take over systems without authentication via HTTP. Although Oracle addressed this issue in its latest Critical Patch Update, many instances remain unpatched. Despite active exploitation, Oracle has not yet classified this vulnerability as exploited in the wild. Internet monitoring firm Shadowserver highlights about 950 vulnerable Oracle EBS instances discoverable online, predominantly in the United States. They have improved their fingerprinting capabilities to monitor these instances more effectively. Organizations using Oracle EBS should prioritize applying the necessary patches immediately. Removing public internet access for non-essential instances is also advisable. For further insights on the Oracle E-Business flaw, read the official news article.

Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed

Write a Reply or Comment

Your email address will not be published. Required fields are marked *