← BACK TO FEED
TAG

erp security1 articles

Oracle E-Business Suite Exploited Before Anyone Even Published the Attack Code

A critical vulnerability in Oracle E-Business Suite's Payments module (CVE-2026-46817, CVSS 9.8) was actively exploited just six weeks after Oracle patched it in May, with attacks beginning before any public proof-of-concept code was released, suggesting the attacker reverse-engineered Oracle's patch or used a private exploit. The targeted, low-volume nature of the attacks — only six attempts from a single source — indicates deliberate reconnaissance rather than broad scanning. The incident reflects a growing trend of attackers rapidly weaponizing enterprise software patches, with around 950 EBS instances currently exposed to the public internet.

5 Jul 2026