Attackers begin exploiting critical Oracle E-Business Suite Payments flaw
THE BRIEF
Threat actors began probing and exploiting CVE-2026-46817, a critical vulnerability in Oracle E-Business Suite Payments. Oracle says unauthenticated attackers can exploit the File Transmissions component over HTTP and potentially take over Oracle Payments. Because EBS is deeply embedded in finance and back-office processes, exploitation can affect both data confidentiality and payment operations.
WHY IT MATTERS
Enterprise financial systems are high-value targets because compromise can expose payment workflows, credentials and sensitive business data. Newly observed exploitation should move this flaw to the top of remediation queues.
WHO SHOULD CARE
ERP owners, finance IT teams, vulnerability managers and CISOs.
WHAT TO DO NOW
- Patch affected Oracle EBS instances
- Check internet exposure
- Review logs for pre-patch exploitation
VERIFICATION NOTE
Backfilled historical brief from a named primary or established reporting source.