Exploitation observed of critical Oracle E-Business Suite flaw

Defused Cyber has reported observed exploitation of CVE-2026-46817 against Oracle E-Business Suite Payments, with honeypot telemetry showing six unauthenticated file-read attempts from a single source on 27 June. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15 and carries a CVSS score of 9.8. NVD describes it as an unauthenticated HTTP issue that can result in takeover of a vulnerable installation. Oracle patched the flaw in its May 2026 Critical Patch Update.

What this means for your organisation

The fix has been available for two months, and observed exploitation means the window for unhurried planning has closed. E-Business Suite handles payments and supplier data, so a takeover hits both the finance function and information subject to privacy requirements. ERP systems are often patched infrequently because changes are heavy to test, and that is exactly why attackers prioritise them.

Berigo recommends

  • Verify whether the May 2026 Oracle update is installed, and prioritise it if not.
  • Check whether E-Business Suite is reachable from the Internet and restrict access to what is necessary.
  • Review logs for unauthenticated file-read attempts going back to before the update was applied.
  • Set a firm maximum deadline for how long critical ERP updates may wait, and have management endorse it.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch