A critical security flaw in Oracle E-Business Suite, tracked as CVE-2026-46817 (CVSS 9.8), is now actively exploited in the wild. The vulnerability, an improper privilege management and authentication flaw in Oracle Payments, allows unauthenticated attackers to compromise susceptible instances via HTTP. It affects versions 12.2.3 through 12.2.15. Oracle released patches in its June 2026 Critical Security Patch Update. Defused Cyber reported exploitation on its honeypots over the weekend, noting no prior public PoC. No details on the threat actor or campaign are available. This follows previous exploitation of CVE-2025-61882 by Cl0p ransomware and CVE-2026-35273 in PeopleSoft Suite by ShinyHunters.
CVEs: CVE-2026-46817, CVE-2025-61882, CVE-2026-35273, CVE-2026-20245
Attack groups: Cl0p, ShinyHunters
Companies: Oracle, Defused Cyber
Products: Oracle E-Business Suite, Oracle Payments, PeopleSoft Suite
Original source: thehackernews.com