As cited
Copy frozen at (site build).
vulnerabilities
Researchers spot exploitation of another critical Oracle defect
Researchers detected six instances of exploitation against a critical Oracle E-Business Suite vulnerability (CVE-2026-46817, CVSS 9.8) within a two-hour window on honeypots, likely representing early reconnaissance and weaponization testing. Shadowserver scans identified approximately 950 potentially vulnerable Oracle E-Business Suite instances, with over half publicly exposed in the United States. Oracle patched the payments processing defect in late May, and the discovery follows a history of similar Oracle products being targeted by ransomware groups and other threat actors in widespread campaigns.
Why it matters: Organizations running Oracle E-Business Suite should verify patch status immediately; over 950 exposed instances exist, and exploitation has already begun despite patch availability.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Researchers spot exploitation of another critical Oracle defect
Researchers detected six instances of exploitation against a critical Oracle E-Business Suite vulnerability (CVE-2026-46817, CVSS 9.8) within a two-hour window on honeypots, likely representing early reconnaissance and weaponization testing. Shadowserver scans identified approximately 950 potentially vulnerable Oracle E-Business Suite instances, with over half publicly exposed in the United States. Oracle patched the payments processing defect in late May, and the discovery follows a history of similar Oracle products being targeted by ransomware groups and other threat actors in widespread campaigns.
Why it matters: Organizations running Oracle E-Business Suite should verify patch status immediately; over 950 exposed instances exist, and exploitation has already begun despite patch availability.
- Source published
- First seen by Cybersecurity Tracker