Over 900 Oracle E-Business Instances Exposed — and Attacks Are Happening Now

If you’re running Oracle E-Business Suite, pay attention.

Shadowserver tracks around 950 Oracle EBS instances exposed online. And attackers are actively hitting them. Defused observed exploitation attempts over the weekend on their Oracle EBS honeypots.

The vulnerability? CVE-2026-46817. CVSS 9.8. It’s an unauthenticated HTTP takeover in Oracle Payments’ File Transmission component. No privileges needed. Low complexity attack. Oracle patched it in the May 2026 Critical Patch Update.

Defused says there’s no known prior exploitation and no public PoC code. That won’t matter for long.

This isn’t an isolated incident. Oracle’s been in the crosshairs all year. Earlier, CISA tagged an Oracle WebLogic Server flaw (CVE-2024-21182) as actively exploited. Clop’s been hitting Oracle EBS since August 2025 using CVE-2025-61882. ShinyHunters went after PeopleSoft with CVE-2026-35273, hitting Nottingham University, NAIC, and Nissan.

CISA has added 44 Oracle vulnerabilities to its known exploited catalog since November 2021. Thirteen were abused by ransomware gangs.

If you’ve got Oracle EBS, check if that May patch was applied. If not, you’re in the crosshairs.

References