Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle E-Business Suite Vulnerability Actively Exploited

Oracle E-Business Suite Vulnerability Actively Exploited

Posted on June 29, 2026 By CWS

Hackers are actively targeting a serious vulnerability in the Oracle E-Business Suite, designated as CVE-2026-46817. This critical flaw, identified over the weekend of June 27–28, 2026, was observed in attacks against honeypot setups, highlighting the urgent need for patching.

Details of the Security Flaw

The vulnerability exists within the Oracle Payments product of Oracle E-Business Suite, specifically affecting the File Transmission component. It carries an alarming CVSS 3.1 score of 9.8, indicating its potential for severe exploitation. This flaw allows attackers with network access via HTTP to fully compromise the system, impacting confidentiality, integrity, and availability.

Versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite are susceptible to this issue. The low complexity and absence of authentication requirements make the vulnerability particularly easy to exploit on a large scale, posing significant risks to unpatched systems.

Active Exploitation Observed

During the last weekend of June 2026, active exploitation of the vulnerability was detected for the first time in the wild. The absence of public proof-of-concept code suggests that attackers may be using privately developed exploits. Threat actors were seen sending targeted POST requests to the Oracle iPayment endpoint, indicating sophisticated attempts to compromise systems.

Notably, an attacker from IP address 45.84.137[.]125, linked to AS136787 PacketHub S.A. in France, focused on port 443. They used crafted XML payloads to exploit the vulnerability, aiming to exfiltrate sensitive data from the file system.

Response and Mitigation Measures

Oracle addressed this vulnerability in its May 2026 Critical Security Patch Update (CSPU), released on May 28, 2026. This update resolved multiple critical vulnerabilities across various Oracle products, including 35 unique CVEs. Following this, a supplementary patch was also released in June 2026 to bolster security measures.

Organizations using Oracle E-Business Suite are advised to implement these patches promptly. Additional recommendations include restricting internet access to /OA_HTML/ paths of Oracle interfaces, auditing server logs for unusual activities, and monitoring for the specific attacker IP and user-agent strings associated with this threat.

In summary, the lack of public exploit code coupled with the emergence of private tools means that unpatched systems are at substantial risk. Immediate action is necessary to mitigate potential compromises.

Cyber Security News Tags:critical flaw, CVE-2026-46817, Cybersecurity, Exploit, exploit prevention, Honeypot, Information Security, network security, Oracle E-Business Suite, patch management, security advisory, security patch, Threat Actors, unauthenticated access, Vulnerability

Post navigation

Previous Post: Malicious Chrome Extension Compromises User Searches
Next Post: Dell Wyse Security Flaws Allow Remote Code Attacks

Related Posts

Secret Blizzard Group’s ApolloShadow Malware Install Root Certificates on Devices to Trust Malicious Sites Secret Blizzard Group’s ApolloShadow Malware Install Root Certificates on Devices to Trust Malicious Sites Cyber Security News
How to Solve Alert Fatigue in Your SOC without Extra Staff or Effort How to Solve Alert Fatigue in Your SOC without Extra Staff or Effort Cyber Security News
Anthropic Alleges Alibaba’s Unauthorized Access to AI Models Anthropic Alleges Alibaba’s Unauthorized Access to AI Models Cyber Security News
Infamous BreachForums Is Back Online With All Accounts and Posts Restored Infamous BreachForums Is Back Online With All Accounts and Posts Restored Cyber Security News
Critical FFmpeg Vulnerabilities Allow Remote Code Execution Critical FFmpeg Vulnerabilities Allow Remote Code Execution Cyber Security News
Windows 11 to Integrate Sysmon for Enhanced Security Windows 11 to Integrate Sysmon for Enhanced Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AmnesiaStealer Malware Targets macOS Users
  • New DRAM Attack Threatens CPU Security Measures
  • Top Microsegmentation Tools for 2026: A Comprehensive Guide
  • Leading Secure Web Gateway Solutions of 2026
  • Apple Warns iPhone Users of Spyware Threats in 110 Countries

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AmnesiaStealer Malware Targets macOS Users
  • New DRAM Attack Threatens CPU Security Measures
  • Top Microsegmentation Tools for 2026: A Comprehensive Guide
  • Leading Secure Web Gateway Solutions of 2026
  • Apple Warns iPhone Users of Spyware Threats in 110 Countries

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark