Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4509 articles · 179422 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-46817KEVEXPLOITEDPATCHED
oracle · e-business_suite

CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi

Description

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. The vulnerability is classified as an improper privilege management flaw. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). First reported exploitation observed on June 29 by Defused threat intelligence company on Oracle E-Business honeypots. CISA confirmed active exploitation on July 16 and issued binding operational directive requiring U.S. federal agencies to patch by July 18, 2026.

Affected Products

VendorProductVersions
oraclee-business_suite12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, 12.2.15

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
oraclee-businesscert_advisory90%

References

  • https://www.oracle.com/security-alerts/cspumay2026.html(vendor-advisory)

Related News (13 articles)

Tier D
The Hacker News5d ago
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
→ No new info (linked only)
Tier D
BleepingComputer6d ago
CISA orders feds to patch actively exploited Oracle flaw by Saturday
→ No new info (linked only)
Tier D
Help Net Security17d ago
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack
→ No new info (linked only)
Tier D
BleepingComputer21d ago
Over 900 Oracle E-Business instances exposed to ongoing attacks
→ No new info (linked only)
Tier D
Help Net Security22d ago
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity22d ago
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
→ No new info (linked only)
Tier D
SecurityWeek22d ago
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
→ No new info (linked only)
Tier D
Heise Security22d ago
Oracle E-Business Suite: Angriffe auf Payments beobachtet
→ No new info (linked only)
Tier D
The Hacker News22d ago
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer23d ago
Hackers now exploit critical Oracle E-Business flaw in attacks
→ No new info (linked only)
Tier B
BSI Advisories54d ago
[NEU] [hoch] Oracle E-Business Suite: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security54d ago
Oracle CSPU: 35 Sicherheitsupdates im Mai
→ No new info (linked only)
Tier C
VulDB54d ago
CVE-2026-46817 | Oracle Payments up to 12.2.15 File Transmission Remote Code Execution
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.oracle.com/security-alerts/cspumay2026.html
CWECWE-269
PublishedMay 28, 2026
Last enriched6d agov8
Tags
active exploitationin-the-wild exploitation
Trending Score71
Source articles13
Independent8
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-35273EXPKEV
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
Trending: 171
CRITICALCVE-2026-62549
CVE-2026-62549: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Trending: 46
CRITICALCVE-2026-60880
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabil
Trending: 46
HIGHCVE-2026-46863
CVE-2026-46863: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supp
Trending: 43
HIGHCVE-2026-62574
CVE-2026-62574: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 28, 2026
Added to CISA KEV
May 28, 2026
Discovered by ZDM
May 28, 2026
Updated: description, activelyExploited
May 28, 2026
Updated: iocs
Jun 29, 2026
Updated: description, tags
Jun 30, 2026
Updated: affectedVersions, exploitAvailable, severity
Jun 30, 2026
Updated: description, tags
Jun 30, 2026
Updated: description
Jul 1, 2026
Actively Exploited
Jul 16, 2026
Exploit Available
Jul 16, 2026
Patch Available
Jul 16, 2026
Updated: affectedVersions, description, cweIds
Jul 16, 2026

Version History

v8
Last enriched 6d ago
v8Tier D6d ago

Expanded affected versions to full range 12.2.3-12.2.15, added CWE-269 (improper privilege management), and updated description with additional technical context including initial exploitation timeline, Defused discovery, CISA confirmation, and federal patching deadline.

affectedVersionsdescriptioncweIds
via BleepingComputer
v7Tier D21d ago

Updated description with new technical details and clarified that the patch is now considered urgent.

description
via BleepingComputer
v6Tier D22d ago

Updated description with details on in-the-wild exploitation and added new tag for in-the-wild exploitation.

descriptiontags
via Help Net Security
v5Tier D22d ago

Updated affected versions to include 12.2.15, marked exploit as available, changed severity to HIGH, and noted no specific IOCs provided.

affectedVersionsexploitAvailableseverity
via Heise Security
v4Tier D22d ago

Updated description with new details on improper privilege management and added tags indicating active exploitation.

descriptiontags
via The Hacker News
v3Tier D23d ago

Marked exploitAvailable as true, updated patchAvailable to null, and added IoCs from the article.

iocs
via BleepingComputer
v2Tier C54d ago

Updated description with new details about Remote Code Execution and changed exploit availability to false.

descriptionactivelyExploited
via VulDB
v154d ago

Initial creation