Multiple outlets report that a critical vulnerability in Oracle E-Business Suite’s Payments component, identified as CVE-2026-46817, is being actively exploited. SecurityWeek and Bleeping Computer cite threat intelligence from Defused, saying unauthenticated attackers can compromise vulnerable Oracle EBS Payments installations. The flaw is described as involving improper privilege management and authentication, enabling attackers to take over susceptible instances. The reported severity is high, with at least one source giving a CVSS score of 9.8.
Help Net Security adds timing details from Defused, stating that decoys detected the first in-the-wild exploitation on 27 June 2026. It characterizes this as occurring roughly six weeks after Oracle’s May 2026 patch and before any public proof-of-concept was released. The Register similarly notes that attacks appear to have targeted systems before public exploit code became available, suggesting attackers may have reverse-engineered the patch.
Across coverage, the focus remains on confirmed early exploitation activity targeting Oracle EBS Payments via CVE-2026-46817, and on the lack of publicly available exploit proof-of-concept at the time initial exploitation was observed.