Oracle E-Business Suite Exploited Before Anyone Even Published the Attack Code
A critical Oracle E-Business Suite vulnerability was being actively exploited just six weeks after Oracle pushed the patch, and before any public proof-of-concept had been published. Someone got there on their own.
Researchers at Defused logged the first known exploitation of CVE-2026-46817 on June 27. The target was the Oracle Payments File Transmission component across E-Business Suite versions 12.2.3 through 12.2.15. The flaw, which Oracle quietly fixed in its May Critical Patch Update, scores a 9.8 on the CVSS scale. That means unauthenticated attackers can read arbitrary files off vulnerable servers. No login required.
What made this stand out wasn't the severity, it was the behaviour. Defused's honeypots recorded just six exploitation attempts from a single source. No broad scanning, no noise. The requests specifically targeted sensitive files, which looks less like opportunistic probing and more like someone quietly validating a working technique. Careful, deliberate, and apparently already armed with a functional exploit before the security research community had published anything.
The implication is fairly uncomfortable: whoever was behind this had either reverse-engineered Oracle's patch or sourced a private exploit through other means. Neither option is reassuring.
The Shadowserver Foundation puts the current number of publicly exposed EBS instances at around 950, mostly US-based. That figure says nothing about patch status, of course. Exposed does not automatically mean vulnerable. But the overlap is rarely zero.
This sits awkwardly alongside some recent history. Earlier this month, researchers flagged exploitation of a critical PeopleSoft zero-day before patches had been widely applied, with ShinyHunters apparently compromising over 100 organisations and making off with HR and payroll data. Then there's Clop's extended campaign against Oracle EBS customers, which went on for months before it even became public knowledge.
Enterprise ERP software has become a reliable target. The software is complex, patching cycles are slow, and critical patch updates can effectively serve as guided tours for anyone willing to reverse-engineer the fixes before customers get around to applying them. Oracle's next patch round can't come soon enough for anyone still running unpatched EBS instances.