A critical vulnerability in Oracle E-Business Suite is being actively exploited in the wild. Defused Cyber reported on Monday that attackers have begun hitting Oracle EBS honeypots over the weekend, making this the first known exploitation of the flaw.
The vulnerability, CVE-2026-46817, carries a CVSS score of 9.8. It is an improper privilege management and authentication flaw in Oracle Payments. An unauthenticated attacker with network access via HTTP can compromise Oracle Payments and take over the affected instance. No credentials needed. No public proof-of-concept code exists, which makes the active exploitation notable.
The flaw impacts Oracle EBS versions 12.2.3 through 12.2.15. Oracle shipped patches last month as part of its Critical Security Patch Update. If you have not applied that update, the clock is ticking.
Details on who is behind the attacks and whether this is opportunistic or targeted remain unclear. What is clear is the pattern. This is the third serious Oracle enterprise product vulnerability to see active exploitation recently. CVE-2025-61882, also CVSS 9.8, was weaponized by the Cl0p ransomware operation last year. Earlier this month, CVE-2026-35273 in PeopleSoft Suite was exploited by ShinyHunters in data theft attacks. Nissan confirmed it was hit through that PeopleSoft flaw, with employee payroll records, bank details, and Social Security numbers potentially exposed.
Jake Knott, principal security researcher at watchTowr, made the point directly: threat actors are exploiting vulnerabilities faster than ever. Organizations should assume compromise and check whether access was obtained before patches were applied, what was accessed, and whether persistence was established.
Patch now. This is not a drill.
