INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oracle E-Business Suite Exploit Code Released
| 2026-07-02 10:35 CRITICAL LOW EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Oracle E-Business Suite vulnerability, CVE-2026-46817, has been under active attack since June 27. Researchers at Defused Cyber have observed the first known exploitation of this flaw on that date, targeting internet-facing instances in the US. The attackers were using a previously unknown exploit to gain access to vulnerable systems over HTTP. This is not an isolated incident; earlier this month, researchers warned that attackers had compromised more than 100 organizations with a similar zero-day vulnerability before patches were widely deployed. As of July 1st, approximately 950 EBS instances remain exposed on the public internet in the US, and experts warn that this flaw could be exploited by active attackers at any time.
Technical Mitigations AI-generated
* Implement a patch management system to ensure timely and effective deployment of critical updates, such as the Oracle Critical Patch Update for E-Business Suite.
* Conduct regular vulnerability assessments and penetration testing on all systems, including those exposed to the public internet, to identify potential entry points for attackers.
* Use secure coding practices and follow best security guidelines when developing or maintaining software applications that interact with sensitive data, such as payment processing in Oracle E-Business Suite.
* Educate employees and users about the importance of patching vulnerabilities promptly, using clear and concise communication channels to ensure timely action on critical updates.
* Consider implementing a "deny-all-privileges" approach for systems exposed to the public internet, where all incoming traffic is blocked until patches are applied or other measures are taken.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35273CVE-2026-35273
CVE-2025-61882CVE-2025-61882
CVE-2026-46817CVE-2026-46817
CVE-2024-21182CVE-2024-21182
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
EUROPE
EUROPE
educationeducation
financefinance
Incident Timeline
November 2021
Ransomware gangs exploited a vulnerability in the Oracle E-Business Suite to target systems from November 13, 2021.
Click on any entity below to view its context and source!
tactic
Ransomware
CISA has added
44 vulnerabilities across various Oracle products
to its catalog of actively exploited flaws since November 2021, 13 of which were also abused by ransomware gangs.
general_metric
44 vulnerabilities
CISA has added
44 vulnerabilities across various Oracle products
to its catalog of actively exploited flaws since November 2021, 13 of which were also abused by ransomware gangs.
data_breach
13 November
CISA has added
44 vulnerabilities across various Oracle products
to its catalog of actively exploited flaws since November 2021, 13 of which were also abused by ransomware gangs.
2025/06/30
Threat actors linked to the Cl0p ransomware operation exploited a critical flaw in Oracle E-Business Suite, with attacks launched as far back as August 2025.
Click on any entity below to view its context and source!
tactic
Ransomware
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
organisation
CVSS
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
vulnerability
CVE-2025-61882
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
general_metric
9.8 unauth
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
organisation
Cl0p
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
2025/07/02
Ransomware attackers exploited a known vulnerability in the Oracle E-Business Suite to target internet-facing servers.
Click on any entity below to view its context and source!
tactic
Ransomware
This latest incident also follows
Clop's lengthy campaign against Oracle E-Business Suite customers
, disclosed last year after researchers found the ransomware crew had targeted internet-facing EBS servers for months before the activity became public.
early August 2025
The Clop extortion gang exploited a previously unknown Oracle E-Business Suite security flaw (CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities and high-profile victims since early August 2025.
Click on any entity below to view its context and source!
tactic
Extortion
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
vulnerability
CVE-2025-61882
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
Harvard University
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
the
University of Pennsylvania
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
Dartmouth College
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
the
University of Phoenix
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
Logitech
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
Washington Post
Since
early August 2025
, the Clop extortion gang
has exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), as well as high-profile victims like
Logitech
,
GlobalLogic
, and the
Washington Post
.
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
organisation
GlobalLogic
Oracle EBS instances exposed online (Shadowserver)
The Clop extortion gang
exploited another Oracle EBS security flaw
(CVE-2025-61882) in zero-day attacks targeting multiple U.S. universities (including
Harvard University
, the
University of Pennsylvania
,
Dartmouth College
, and the
University of Phoenix
), the
Washington Post
,
Logitech
, and GlobalLogic since
early August 2025
.
August 2025
Threat actors linked to the Cl0p ransomware operation exploited a critical flaw in Oracle E-Business Suite, with attacks launched as far back as August 2025.
Click on any entity below to view its context and source!
tactic
Ransomware
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
organisation
CVSS
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
vulnerability
CVE-2025-61882
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
general_metric
9.8 unauth
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
organisation
Cl0p
Late last year, another critical flaw in the same product (
CVE-2025-61882
, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.
May 2026
Attackers exploited a vulnerability in the Oracle E-Business Suite.
Click on any entity below to view its context and source!
organisation
Oracle
Oracle has patched this flaw with security updates released as part of its
May 2026 Critical Security Patch Update
and urged customers to patch their systems immediately.
Oracle released security updates to address the vulnerability with its
May 2026 Critical Security Patch Update
and urged customers to patch their systems immediately.
2026/05/31
Threat actors exploited a previously unknown vulnerability in the Oracle E-Business Suite.
Click on any entity below to view its context and source!
organisation
Critical Security Patch Update
Patches for the flaw were
shipped
by Oracle as part of its Critical Security Patch Update last month.
2026/06/01
Threat actors exploited a high-severity Oracle WebLogic Server flaw (CVE-2024-21182) in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) recommendation to apply Critical Patch Update patches immediately on June 1, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2024-21182
Oracle EBS instances exposed online (Shadowserver)
Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
also tagged
a high-severity Oracle WebLogic Server flaw (CVE-2024-21182)
attribution
Oracle WebLogic
Oracle EBS instances exposed online (Shadowserver)
Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
also tagged
a high-severity Oracle WebLogic Server flaw (CVE-2024-21182)
tactic
T1584.004 - Server
Oracle EBS instances exposed online (Shadowserver)
Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
also tagged
a high-severity Oracle WebLogic Server flaw (CVE-2024-21182)
June 11
Mandiant and Google's Threat Intelligence Group published an analysis of a ShinyHunters campaign targeting the Oracle E-Business Suite on June 12.
Click on any entity below to view its context and source!
attribution
Mandiant
Mandiant and Google’s Threat Intelligence Group published an analysis of an active
ShinyHunters
campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited.
attribution
Google’s Threat Intelligence Group
Mandiant and Google’s Threat Intelligence Group published an analysis of an active
ShinyHunters
campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited.
attribution
ShinyHunters
Mandiant and Google’s Threat Intelligence Group published an analysis of an active
ShinyHunters
campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited.
June 27
Researchers at Defused discovered that the Oracle E-Business Suite flaw CVE-2026-46817 was exploited on June 27.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-46817
Researchers at Defused
said
they observed the first known exploitation of CVE-2026-46817 on June 27.
Jun 30, 2026
Threat actors exploited a known vulnerability in the Oracle E-Business Suite to gain unauthorized access.
2026/07/01
Attackers exploited a known flaw in Oracle E-Business Suite instances to gain access.
Click on any entity below to view its context and source!
general_metric
950 EBS instances
Earlier today, internet security watchdog Shadowserver
also warned
that it tracks
around 950 Oracle EBS instances
exposed online.
organisation
Oracle EBS
Earlier today, internet security watchdog Shadowserver
also warned
that it tracks
around 950 Oracle EBS instances
exposed online.
May 27 and June 9
ShinyHunters exploited a critical Oracle E-Business Suite flaw to gain unauthenticated remote code execution in the PeopleSoft Suite between May 27 and June 9.
Click on any entity below to view its context and source!
organisation
ShinyHunters
Weeks later, Oracle
mitigated a critical PeopleSoft Suite zero-day
(CVE-2026-35273) that was
exploited by the ShinyHunters extortion gang
to gain unauthenticated remote code execution
between May 27 and June 9
and to steal data from many organizations worldwide, including
Nottingham University
and
the National Association of Insurance Commissioners (NAIC)
.
tactic
Extortion
Weeks later, Oracle
mitigated a critical PeopleSoft Suite zero-day
(CVE-2026-35273) that was
exploited by the ShinyHunters extortion gang
to gain unauthenticated remote code execution
between May 27 and June 9
and to steal data from many organizations worldwide, including
Nottingham University
and
the National Association of Insurance Commissioners (NAIC)
.
vulnerability
CVE-2026-35273
Weeks later, Oracle
mitigated a critical PeopleSoft Suite zero-day
(CVE-2026-35273) that was
exploited by the ShinyHunters extortion gang
to gain unauthenticated remote code execution
between May 27 and June 9
and to steal data from many organizations worldwide, including
Nottingham University
and
the National Association of Insurance Commissioners (NAIC)
.
tactic
Remote Code Execution
Weeks later, Oracle
mitigated a critical PeopleSoft Suite zero-day
(CVE-2026-35273) that was
exploited by the ShinyHunters extortion gang
to gain unauthenticated remote code execution
between May 27 and June 9
and to steal data from many organizations worldwide, including
Nottingham University
and
the National Association of Insurance Commissioners (NAIC)
.
organisation
Nottingham University
Weeks later, Oracle
mitigated a critical PeopleSoft Suite zero-day
(CVE-2026-35273) that was
exploited by the ShinyHunters extortion gang
to gain unauthenticated remote code execution
between May 27 and June 9
and to steal data from many organizations worldwide, including
Nottingham University
and
the National Association of Insurance Commissioners (NAIC)
.
organisation
NAIC
Weeks later, Oracle
mitigated a critical PeopleSoft Suite zero-day
(CVE-2026-35273) that was
exploited by the ShinyHunters extortion gang
to gain unauthenticated remote code execution
between May 27 and June 9
and to steal data from many organizations worldwide, including
Nottingham University
and
the National Association of Insurance Commissioners (NAIC)
.
May 27 to June 9
The attackers exploited a vulnerability in Oracle E-Business Suite that was active from May 27 to June 9.
2026/07/02
Attackers are exploiting a critical flaw in Oracle E-Business Suite's Payments module, CVE-2026-46817.
Click on any entity below to view its context and source!
organisation
The Shadowserver Foundation
The Shadowserver Foundation
said
it currently sees around 950 EBS instances exposed to the public internet, the majority in the US, although it stressed that figure says nothing about whether they're vulnerable or fully patched.
reads the post published by The Shadowserver Foundation.
organisation
EBS
The Shadowserver Foundation
said
it currently sees around 950 EBS instances exposed to the public internet, the majority in the US, although it stressed that figure says nothing about whether they're vulnerable or fully patched.
Now, Internet monitoring firm Shadowserver counts roughly
950 EBS instances
still reachable from the public internet, most of them in the United States.
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw.
This security flaw was found in the File Transmission component of EBS's Oracle Payments product and enables unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks.
organisation
Shadowserver
Now, Internet monitoring firm Shadowserver counts roughly
950 EBS instances
still reachable from the public internet, most of them in the United States.
victims
100 organizations
Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.
Earlier this month, researchers warned that attackers had exploited a critical PeopleSoft zero-day before patches were widely deployed, with
the ShinyHunters crew claiming to have compromised more than 100 organizations.
organisation
Mandiant
Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.
organisation
Oracle EBS
CVE-2026-46817 exploitation (Defused)
Internet security watchdog group Shadowserver now
tracks over 450 Oracle EBS instances
exposed online, with nearly 200 in the United States and in Europe.
If your organization runs Oracle EBS and hasn’t applied it, that’s the immediate priority.
organisation
File Transmission
This security flaw was found in the File Transmission component of EBS's Oracle Payments product and enables unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks.
The vulnerability (tracked as
CVE-2026-46817
) was found in the File Transmission component of EBS's Oracle Payments product and allows malicious actors without privileges and with HTTP network access to take over vulnerable systems through low-complexity attacks.
organisation
Oracle Payments
This security flaw was found in the File Transmission component of EBS's Oracle Payments product and enables unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks.
The vulnerability (tracked as
CVE-2026-46817
) was found in the File Transmission component of EBS's Oracle Payments product and allows malicious actors without privileges and with HTTP network access to take over vulnerable systems through low-complexity attacks.
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments.
The vulnerability, tracked as
CVE-2026-46817
(CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances.
The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP.
organisation
Oracle E-Business Suite Flaw Under
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed.
organisation
Oracle E-Business
"CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited.
“CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots.”
CVE-2026-46817 has since come under active exploitation, with Defused Cyber
noting
on Monday that "over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots," adding "this vulnerability has no known previous exploitation and no public PoC
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
Oracle E-Business
)
Hackers now exploit critical Oracle E-Business flaw in attacks.
organisation
Oracle E-Business Suite
This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as
CVE-2026-46817
, is being actively exploited.
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments.
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild.
Ravie Lakshmanan
Jun 30, 2026
Vulnerability / Enterprise Software
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released.
organisation
Vulnerability / Enterprise
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild.
Ravie Lakshmanan
Jun 30, 2026
Vulnerability / Enterprise Software
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
organisation
CVE-2026-46817
CVE-2026-46817 has since come under active exploitation, with Defused Cyber
noting
on Monday that "over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots," adding "this vulnerability has no known previous exploitation and no public PoC
organisation
Defused
"
While Oracle has yet to flag the CVE-2026-46817 flaw as exploited in the wild, Defused said on Monday that attackers are now actively exploiting it, with the first attempts spotted over the weekend.
infrastructure
12.2.3
The attackers were targeting the Oracle Payments File Transmission component in E-Business Suite releases 12.2.3 through 12.2.15, they said.
The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP.
"
The shortcoming impacts versions from 12.2.3 through 12.2.15.
infrastructure
12.2.15
The attackers were targeting the Oracle Payments File Transmission component in E-Business Suite releases 12.2.3 through 12.2.15, they said.
The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP.
"
The shortcoming impacts versions from 12.2.3 through 12.2.15.
organisation
the Oracle Payments File Transmission
The attackers were targeting the Oracle Payments File Transmission component in E-Business Suite releases 12.2.3 through 12.2.15, they said.
infrastructure
9.8
The vulnerability,
fixed in Oracle's May Critical Patch Update
, carries a CVSS score of 9.8 and allows unauthenticated attackers to read arbitrary files from vulnerable servers.
organisation
CVSS
The vulnerability,
fixed in Oracle's May Critical Patch Update
, carries a CVSS score of 9.8 and allows unauthenticated attackers to read arbitrary files from vulnerable servers.
organisation
Big Red's
cyber-crime
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Attackers appear to have reverse-engineered Big Red's patch
Attackers have been caught exploiting a critical flaw in Oracle E-Business Suite's Payments module just six weeks after Oracle patched it – and before any public proof-of-concept exploit was available.
organisation
Oracle E-Business Suite's
cyber-crime
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Attackers appear to have reverse-engineered Big Red's patch
Attackers have been caught exploiting a critical flaw in Oracle E-Business Suite's Payments module just six weeks after Oracle patched it – and before any public proof-of-concept exploit was available.
organisation
Oracle
cyber-crime
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Attackers appear to have reverse-engineered Big Red's patch
Attackers have been caught exploiting a critical flaw in Oracle E-Business Suite's Payments module just six weeks after Oracle patched it – and before any public proof-of-concept exploit was available.
Despite researchers confirming active exploitation of the vulnerabilities, Oracle hasn’t officially flagged this vulnerability as exploited in the wild.
organisation
ShinyHunters
Earlier this month, researchers warned that attackers had exploited a critical PeopleSoft zero-day before patches were widely deployed, with
the ShinyHunters crew claiming to have compromised more than 100 organizations.
Earlier this month, the company addressed a critical missing authentication zero-day vulnerability in PeopleSoft Suite (
CVE-2026-35273
, CVSS score: 9.8) that was actively exploited in ShinyHunters data theft and extortion attacks.
organisation
Oracle ERP
The newly exploited EBS vulnerability is probably not the last Oracle ERP bug to be targeted.
organisation
Oracle PeopleSoft’s Environment Management
The flaw
CVE-2026-35273
is a remote code execution vulnerability in Oracle PeopleSoft’s Environment Management component.
organisation
CVE-2026-35273
Weeks later, the company
mitigated a critical PeopleSoft Suite zero-day vulnerability
(CVE-2026-35273), which was
actively exploited in ShinyHunter data theft attacks
and allows unauthenticated remote code execution.
organisation
ShinyHunter
Weeks later, the company
mitigated a critical PeopleSoft Suite zero-day vulnerability
(CVE-2026-35273), which was
actively exploited in ShinyHunter data theft attacks
and allows unauthenticated remote code execution.
organisation
Nissan
Most recently, Nissan
also warned of a data breach
affecting current and former employees following the compromise of its Oracle PeopleSoft instance.
organisation
Oracle PeopleSoft
Most recently, Nissan
also warned of a data breach
affecting current and former employees following the compromise of its Oracle PeopleSoft instance.
Oracle PeopleSoft Enterprise PeopleTools is the underlying technology platform used to build, run, administer, and customize Oracle PeopleSoft applications.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking,
Oracle E-Business
)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
–
Oracle
, hacking)
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
Shadowserver’s
Shadowserver’s scan suggests the exposed population is not small, and active exploitation without a public proof-of-concept means the attacker community is already ahead of most defenders on this one.
organisation
the Environment Management Hub
Just network access to the Environment Management Hub endpoint and you can take over the server.
organisation
Automaker Nissan
Automaker Nissan has since
acknowledged
that it was among those impacted, stating it was the victim of a break-in that involved the exploitation of the PeopleSoft flaw, potentially exposing payroll records, bank details, Social Security numbers, and other personal and financial data belong to its employees in the U.S., Canada, Mexico, and Brazil.
organisation
PeopleSoft
Automaker Nissan has since
acknowledged
that it was among those impacted, stating it was the victim of a break-in that involved the exploitation of the PeopleSoft flaw, potentially exposing payroll records, bank details, Social Security numbers, and other personal and financial data belong to its employees in the U.S., Canada, Mexico, and Brazil.
organisation
Social Security
Automaker Nissan has since
acknowledged
that it was among those impacted, stating it was the victim of a break-in that involved the exploitation of the PeopleSoft flaw, potentially exposing payroll records, bank details, Social Security numbers, and other personal and financial data belong to its employees in the U.S., Canada, Mexico, and Brazil.
organisation
the NIST National Vulnerability Database
"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments," according to a description of the flaw in the NIST National Vulnerability Database (NVD).
organisation
NVD
"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments," according to a description of the flaw in the NIST National Vulnerability Database (NVD).
organisation
Knott
"
Knott also pointed out that threat actors are exploiting vulnerabilities faster than ever before, urging organizations to assume compromise and activate incident response processes to determine whether access was obtained before patches were applied, what was accessed, and whether persistence was established.
Tactical Metrics
Metrics
infrastructure
12.2.3
Software Version
Click for context!
The attackers were targeting the Oracle Payments File Transmission component in E-Business Suite releases 12.2.3 through 12.2.15, they said.
The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP.
"
The shortcoming impacts versions from 12.2.3 through 12.2.15.
Metrics
infrastructure
12.2.15
Software Version
The attackers were targeting the Oracle Payments File Transmission component in E-Business Suite releases 12.2.3 through 12.2.15, they said.
The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP.
"
The shortcoming impacts versions from 12.2.3 through 12.2.15.
Metrics
infrastructure
9.8
Software Version
The vulnerability,
fixed in Oracle's May Critical Patch Update
, carries a CVSS score of 9.8 and allows unauthenticated attackers to read arbitrary files from vulnerable servers.
Metrics
victims
100
Organizations
Earlier this month, researchers warned that attackers had exploited a critical PeopleSoft zero-day before patches were widely deployed, with
the ShinyHunters crew claiming to have compromised more than 100 organizations.
Sixty-eight percent of the more than 100 organizations Mandiant notified were universities and colleges, most of them in the United States.
Metrics
data_breach
13
November
CISA has added
44 vulnerabilities across various Oracle products
to its catalog of actively exploited flaws since November 2021, 13 of which were also abused by ransomware gangs.
Intelligence Sources
The Hacker News
2026-06-30
BleepingComputer
2026-06-29
Hackers now exploit critical Oracle E-Business flaw in attacks
BleepingComputer
BleepingComputer
2026-07-01
Over 900 Oracle E-Business instances exposed to ongoing attacks
BleepingComputer
Security Affairs
2026-06-30
Security Affairs
2026-07-01
The Register - Cybercrime
2026-07-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-03T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
48x
organisation
Identified Entity
The Shadowserver Foundation
entity
16x
timeline
Temporal Reference
2025/07/02
date
11x
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
4x
target region
Target Country
United States
country
4x
tactic
Cyber Operation Type
Ransomware
tactic
4x
vulnerability
Exploited CVE
CVE-2026-46817
cve
3x
infrastructure
Software Version
12.2.3
version
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
general metric
%
54
%
Contextual Telemetry
Context Block
12 METRICS
general metric
Ebs Instances
950
ebs instances
vulnerability
CVSS Score
10
score
victims
Organizations
100
organizations
general metric
Vulnerabilities
44
vulnerabilities
data breach
November
13
november
general metric
Unauth
10
unauth
general metric
E - Business Suite
900
e - business suite
industry
Targeted Sector
Technology
sector
general metric
Jun
30
jun
target region
Target Region
EUROPE
region
general metric
Oracle Ebs
450
oracle ebs
general metric
Wild
13
wild
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.