CVE-2026-46817
published 2026-05-28CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2026-07-18
Exploited in the wild
EPSS
13.02%
96.1th percentile
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | 12.2.3 – 12.2.15 | — |
| oracle_corporation | oracle_payments | 12.2.3 – 12.2.15 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check Point IPS signature available for CVE-2026-46817 detection ↗
- →Approximately 950 internet-exposed Oracle E-Business Suite instances were targeted; prioritize scanning for externally reachable EBS deployments ↗
- →Exploitation vector is unauthenticated HTTP network access; monitor for unexpected unauthenticated requests to Oracle Payments endpoints, particularly the File Transmission component ↗
- ·Affected versions are Oracle E-Business Suite 12.2.3 through 12.2.15 only; versions outside this range are not listed as affected ↗
- ·No details are currently available on the specific exploitation technique, threat actor identity, or whether attacks are opportunistic or targeted ↗
- ·Patches were released by Oracle in the Critical Security Patch Update prior to active exploitation being observed; patch status should be verified before assuming protection ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Payments up to 12.2.15 File Transmission Remote Code Execution
vuldb·2026-05-28·CVSS 9.8
CVE-2026-46817 [CRITICAL] Oracle Payments up to 12.2.15 File Transmission Remote Code Execution
A vulnerability classified as critical has been found in Oracle Payments up to 12.2.15. The affected element is an unknown function of the component File Transmission. The manipulation leads to Remote Code Execution.
This vulnerability is documented as CVE-2026-46817. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-pv4m-gf99-c5jr: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)
ghsa_unreviewed·2026-05-28
CVE-2026-46817 [CRITICAL] CWE-269 GHSA-pv4m-gf99-c5jr: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle E-Business Suite Improper Privilege Management
vulncheck·2026·CVSS 9.8
CVE-2026-46817 [CRITICAL] Oracle E-Business Suite Improper Privilege Management
Oracle E-Business Suite Improper Privilege Management
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected: Oracle E-Business Suite
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.
CISA
Oracle E-Business Suite Improper Privilege Management Vulnerability
cisa·2026-07-15·CVSS 9.8
CVE-2026-46817 [CRITICAL] CWE-269 Oracle E-Business Suite Improper Privilege Management Vulnerability
Vulnerability: Oracle E-Business Suite Improper Privilege Management Vulnerability
Affected: Oracle E-Business Suite
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating
No detection rules found.
No public exploits indexed.
Hackernews
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
blogs_hackernews·2026-07-16
CVE-2026-46817 ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
A lot of this week’s trouble starts with something that looks close enough.
A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation.
Old bugs are back, weak defaults are earning their keep, and some attack paths are so plain they barely feel like research. Here’s the mess.
Cybersecurity researchers 11 malicious NuGet packages published as .NET command-line tools that present themselves as game utilities, bots, and
Checkpoint
6th July – Threat Intelligence Report
blogs_checkpoint·2026-07-06
CVE-2026-46817 6th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found ransomware on portions of its server environment and is assessing whether personal data was accessed or exfiltrated.
Indra
Hackernews
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
blogs_hackernews·2026-06-30·CVSS 9.8
CVE-2026-46817 [CRITICAL] Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances.
"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments," according to a description of the flaw in the NIST National Vulnerability Database (NVD
2026-05-28
Published
2026-07-15
Added to CISA KEV
Exploited in the wild