INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oracle E-Business Suite Exploit Code Released

| 2026-07-02 10:35 CRITICAL LOW EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Oracle E-Business Suite vulnerability, CVE-2026-46817, has been under active attack since June 27. Researchers at Defused Cyber have observed the first known exploitation of this flaw on that date, targeting internet-facing instances in the US. The attackers were using a previously unknown exploit to gain access to vulnerable systems over HTTP. This is not an isolated incident; earlier this month, researchers warned that attackers had compromised more than 100 organizations with a similar zero-day vulnerability before patches were widely deployed. As of July 1st, approximately 950 EBS instances remain exposed on the public internet in the US, and experts warn that this flaw could be exploited by active attackers at any time.
Technical Mitigations AI-generated
* Implement a patch management system to ensure timely and effective deployment of critical updates, such as the Oracle Critical Patch Update for E-Business Suite. * Conduct regular vulnerability assessments and penetration testing on all systems, including those exposed to the public internet, to identify potential entry points for attackers. * Use secure coding practices and follow best security guidelines when developing or maintaining software applications that interact with sensitive data, such as payment processing in Oracle E-Business Suite. * Educate employees and users about the importance of patching vulnerabilities promptly, using clear and concise communication channels to ensure timely action on critical updates. * Consider implementing a "deny-all-privileges" approach for systems exposed to the public internet, where all incoming traffic is blocked until patches are applied or other measures are taken.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35273CVE-2026-35273 CVE-2025-61882CVE-2025-61882 CVE-2026-46817CVE-2026-46817 CVE-2024-21182CVE-2024-21182
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE educationeducation financefinance
Incident Timeline
‎November 2021
Ransomware gangs exploited a vulnerability in the Oracle E-Business Suite to target systems from November 13, 2021.
tactic Ransomware
general_metric 44 vulnerabilities
data_breach 13 November
‎2025/06/30
Threat actors linked to the Cl0p ransomware operation exploited a critical flaw in Oracle E-Business Suite, with attacks launched as far back as August 2025.
tactic Ransomware
organisation CVSS
vulnerability CVE-2025-61882
general_metric 9.8 unauth
organisation Cl0p
‎2025/07/02
Ransomware attackers exploited a known vulnerability in the Oracle E-Business Suite to target internet-facing servers.
tactic Ransomware
‎early August 2025
The Clop extortion gang exploited a previously unknown Oracle E-Business Suite security flaw (CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities and high-profile victims since early August 2025.
tactic Extortion
vulnerability CVE-2025-61882
organisation Harvard University
organisation the University of Pennsylvania
organisation Dartmouth College
organisation the University of Phoenix
organisation Logitech
organisation Washington Post
organisation GlobalLogic
‎August 2025
Threat actors linked to the Cl0p ransomware operation exploited a critical flaw in Oracle E-Business Suite, with attacks launched as far back as August 2025.
tactic Ransomware
organisation CVSS
vulnerability CVE-2025-61882
general_metric 9.8 unauth
organisation Cl0p
‎May 2026
Attackers exploited a vulnerability in the Oracle E-Business Suite.
organisation Oracle
‎2026/05/31
Threat actors exploited a previously unknown vulnerability in the Oracle E-Business Suite.
organisation Critical Security Patch Update
‎2026/06/01
Threat actors exploited a high-severity Oracle WebLogic Server flaw (CVE-2024-21182) in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) recommendation to apply Critical Patch Update patches immediately on June 1, 2026.
vulnerability CVE-2024-21182
attribution Oracle WebLogic
tactic T1584.004 - Server
‎June 11
Mandiant and Google's Threat Intelligence Group published an analysis of a ShinyHunters campaign targeting the Oracle E-Business Suite on June 12.
attribution Mandiant
attribution Google’s Threat Intelligence Group
attribution ShinyHunters
‎June 27
Researchers at Defused discovered that the Oracle E-Business Suite flaw CVE-2026-46817 was exploited on June 27.
vulnerability CVE-2026-46817
‎Jun 30, 2026
Threat actors exploited a known vulnerability in the Oracle E-Business Suite to gain unauthorized access.
‎2026/07/01
Attackers exploited a known flaw in Oracle E-Business Suite instances to gain access.
general_metric 950 EBS instances
organisation Oracle EBS
‎May 27 and June 9
ShinyHunters exploited a critical Oracle E-Business Suite flaw to gain unauthenticated remote code execution in the PeopleSoft Suite between May 27 and June 9.
organisation ShinyHunters
tactic Extortion
vulnerability CVE-2026-35273
tactic Remote Code Execution
organisation Nottingham University
organisation NAIC
‎May 27 to June 9
The attackers exploited a vulnerability in Oracle E-Business Suite that was active from May 27 to June 9.
‎2026/07/02
Attackers are exploiting a critical flaw in Oracle E-Business Suite's Payments module, CVE-2026-46817.
organisation The Shadowserver Foundation
organisation EBS
organisation Shadowserver
victims 100 organizations
organisation Mandiant
organisation Oracle EBS
organisation File Transmission
organisation Oracle Payments
organisation Oracle E-Business Suite Flaw Under
organisation Oracle E-Business
organisation Oracle E-Business Suite
organisation Vulnerability / Enterprise
organisation CVE-2026-46817
organisation Defused
infrastructure 12.2.3
infrastructure 12.2.15
organisation the Oracle Payments File Transmission
infrastructure 9.8
organisation CVSS
organisation Big Red's
organisation Oracle E-Business Suite's
organisation Oracle
organisation ShinyHunters
organisation Oracle ERP
organisation Oracle PeopleSoft’s Environment Management
organisation CVE-2026-35273
organisation ShinyHunter
organisation Nissan
organisation Oracle PeopleSoft
organisation SecurityAffairs
organisation EDR
organisation Shadowserver’s
organisation the Environment Management Hub
organisation Automaker Nissan
organisation PeopleSoft
organisation Social Security
organisation the NIST National Vulnerability Database
organisation NVD
organisation Knott
Tactical Metrics
Metrics
infrastructure
‎12.2.3
Software Version
Metrics
infrastructure
‎12.2.15
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
victims
100
Organizations
Metrics
data_breach
13
November