Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle E-Business Suite Vulnerability Actively Exploited

Oracle E-Business Suite Vulnerability Actively Exploited

Posted on June 29, 2026 By CWS

Hackers are actively targeting a serious vulnerability in the Oracle E-Business Suite, designated as CVE-2026-46817. This critical flaw, identified over the weekend of June 27–28, 2026, was observed in attacks against honeypot setups, highlighting the urgent need for patching.

Details of the Security Flaw

The vulnerability exists within the Oracle Payments product of Oracle E-Business Suite, specifically affecting the File Transmission component. It carries an alarming CVSS 3.1 score of 9.8, indicating its potential for severe exploitation. This flaw allows attackers with network access via HTTP to fully compromise the system, impacting confidentiality, integrity, and availability.

Versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite are susceptible to this issue. The low complexity and absence of authentication requirements make the vulnerability particularly easy to exploit on a large scale, posing significant risks to unpatched systems.

Active Exploitation Observed

During the last weekend of June 2026, active exploitation of the vulnerability was detected for the first time in the wild. The absence of public proof-of-concept code suggests that attackers may be using privately developed exploits. Threat actors were seen sending targeted POST requests to the Oracle iPayment endpoint, indicating sophisticated attempts to compromise systems.

Notably, an attacker from IP address 45.84.137[.]125, linked to AS136787 PacketHub S.A. in France, focused on port 443. They used crafted XML payloads to exploit the vulnerability, aiming to exfiltrate sensitive data from the file system.

Response and Mitigation Measures

Oracle addressed this vulnerability in its May 2026 Critical Security Patch Update (CSPU), released on May 28, 2026. This update resolved multiple critical vulnerabilities across various Oracle products, including 35 unique CVEs. Following this, a supplementary patch was also released in June 2026 to bolster security measures.

Organizations using Oracle E-Business Suite are advised to implement these patches promptly. Additional recommendations include restricting internet access to /OA_HTML/ paths of Oracle interfaces, auditing server logs for unusual activities, and monitoring for the specific attacker IP and user-agent strings associated with this threat.

In summary, the lack of public exploit code coupled with the emergence of private tools means that unpatched systems are at substantial risk. Immediate action is necessary to mitigate potential compromises.

Cyber Security News Tags:critical flaw, CVE-2026-46817, Cybersecurity, Exploit, exploit prevention, Honeypot, Information Security, network security, Oracle E-Business Suite, patch management, security advisory, security patch, Threat Actors, unauthenticated access, Vulnerability

Post navigation

Previous Post: Malicious Chrome Extension Compromises User Searches
Next Post: Dell Wyse Security Flaws Allow Remote Code Attacks

Related Posts

Conducting Risk Assessments That Drive Business Value Conducting Risk Assessments That Drive Business Value Cyber Security News
New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender Cyber Security News
FastJson RCE Vulnerability Threatens US Organizations FastJson RCE Vulnerability Threatens US Organizations Cyber Security News
AI Accelerates Zero-Day Exploits, Increasing Cyber Risks AI Accelerates Zero-Day Exploits, Increasing Cyber Risks Cyber Security News
Critical Flaw in KMW CCTV Allows Unauthorized Access Critical Flaw in KMW CCTV Allows Unauthorized Access Cyber Security News
Critical GoAnywhere MFT Platform Vulnerability Exposes Enterprises to Remote Exploitation Critical GoAnywhere MFT Platform Vulnerability Exposes Enterprises to Remote Exploitation Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign
  • Carbonato Botnet Targets Docker Hosts with Hermes AI
  • OpenAI Agents Breach Sandbox, Create 80,000 Payloads
  • Ex-Soldier Sentenced for Hacking AT&T and Verizon

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign
  • Carbonato Botnet Targets Docker Hosts with Hermes AI
  • OpenAI Agents Breach Sandbox, Create 80,000 Payloads
  • Ex-Soldier Sentenced for Hacking AT&T and Verizon

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark