-
CISA confirmed that attackers are actively exploiting a critical Oracle E-Business Suite flaw tracked as CVE-2026-46817.
-
The security bug lets attackers break into Oracle Payments over HTTP without needing a username or password.
-
Federal agencies must apply Oracle’s security update by July 18, while researchers have already found more than 1,000 internet-facing Oracle E-Business Suite servers.
Cybercriminals are already taking advantage of a critical security flaw in Oracle E-Business Suite. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has now confirmed the attacks.
The agency added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog after finding that attackers are abusing it in real-world incidents.
The flaw is tracked as CVE-2026-46817. It affects the Oracle Payments File Transmission feature in Oracle E-Business Suite. Oracle gave it the highest possible severity score of 9.8 out of 10.
According to Oracle, the flaw affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. An attacker only needs HTTP access to a vulnerable server. They do not need to log in first.
Oracle explained that a successful attack could let someone take control of Oracle Payments. That access could also lead to a full takeover of the affected system. Many organizations use Oracle E-Business Suite for important business work.
The platform handles financial records, payments, invoices, purchasing, and other daily operations. Because of that, a successful attack could expose valuable business data.
CISA has ordered U.S. federal civilian agencies to fix the issue by July 18, 2026, under Binding Operational Directive 22-01. The deadline only applies to federal agencies. Still, security experts believe every organization using affected Oracle systems should act immediately. Installing Oracle’s available security updates remains the safest option.
Researchers Spotted Attacks Before Public Exploit Appeared
Researchers at Defused Cyber noticed something unusual while watching their Oracle E-Business Suite honeypots. They saw attackers trying to exploit the flaw before anyone had released a public proof-of-concept. That discovery suggests the attackers either found the weakness on their own or had access to a private exploit.
Active exploitation of vulnerabilities is a growing concern. Not too long ago, Microsoft also released a fix for a critical Defender privilege escalation bug being exploited in the wild.
The researchers also scanned the internet for exposed Oracle E-Business Suite systems. Their first scan found more than 900 publicly accessible servers. Later scans pushed that number above 1,000 internet-facing systems.
The researchers also warned that not every exposed server is necessarily vulnerable. They also said an exposed server does not automatically mean it has already been compromised.
Still, the numbers show that many organizations could be at risk. The vulnerable feature accepts HTTP connections. It also does not require valid login details before an attack begins.
That combination makes internet-facing Oracle E-Business Suite servers much easier to target if administrators have not installed Oracle’s security updates.
According to Oracle, attackers can exploit the flaw remotely without authentication. That makes quick patching even more important for affected organizations.
Oracle’s Business Platform Remains a Valuable Target
Oracle E-Business Suite is widely used by government agencies, banks, hospitals, universities, manufacturers, and many other large organizations. These organizations depend on the software to manage payments and other important business tasks every day. For that, criminals often look for weaknesses in the platform.
Security researchers said that taking control of Oracle Payments could give attackers access to payment processes and financial records. It could also help them move deeper into an organization’s network.
That kind of access may attract ransomware gangs as well as espionage groups looking for valuable business information. CISA’s decision to place CVE-2026-46817 in the KEV Catalog also changes the situation. The listing confirms that the vulnerability is no longer just a possible threat.
Instead, attackers are already using it against real targets. Organizations running affected Oracle E-Business Suite versions should identify vulnerable systems as soon as possible. They should also install Oracle’s available security updates, review systems that are exposed to the internet, and watch closely for signs of unauthorized activity.
Delaying Updates could Give Attackers an Easy Opportunity
The attacks have already started, and researchers continue finding Oracle E-Business Suite systems exposed online. That means unpatched organizations may remain easy targets while attackers keep scanning the internet for vulnerable servers. According to Oracle, attackers do not need valid account credentials before launching an attack. HTTP access to a vulnerable server is enough.
According to Defused Cyber, attack attempts appeared before any public exploit became available. That finding suggests some threat actors already had working attack methods before the wider security community knew about them. CISA’s emergency directive shows how seriously the agency views the threat. Federal agencies now have a short deadline to secure affected systems.
Although that order only covers U.S. civilian federal agencies, the same risk applies to any organization running vulnerable Oracle E-Business Suite versions. Organizations that delay installing Oracle’s security updates could leave critical financial systems exposed while attackers continue searching for easy targets.