cbcvebase.
CVE-2026-46817
published 2026-05-28

CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2026-07-18
Exploited in the wild
EPSS
13.02%
96.1th percentile
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

2 ranges
VendorProductVersion rangeFixed in
oraclee-business_suite12.2.3 – 12.2.15
oracle_corporationoracle_payments12.2.3 – 12.2.15

Detection & IOCsextracted from sources · hover to see the quote

  • Check Point IPS signature available for CVE-2026-46817 detection
  • Approximately 950 internet-exposed Oracle E-Business Suite instances were targeted; prioritize scanning for externally reachable EBS deployments
  • Exploitation vector is unauthenticated HTTP network access; monitor for unexpected unauthenticated requests to Oracle Payments endpoints, particularly the File Transmission component
  • ·Affected versions are Oracle E-Business Suite 12.2.3 through 12.2.15 only; versions outside this range are not listed as affected
  • ·No details are currently available on the specific exploitation technique, threat actor identity, or whether attacks are opportunistic or targeted
  • ·Patches were released by Oracle in the Critical Security Patch Update prior to active exploitation being observed; patch status should be verified before assuming protection

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.