Close Menu
    What's Hot

    How SpaceX wants to fuel Starship’s next phase with a Texas pipeline

    In pictures: Venezuela earthquakes death toll surpasses 1,700 | Earthquakes News

    Lewis Hamilton will be confident of challenging for victory at British GP, says his former team-mate Jenson Button | F1 News

    Facebook X (Twitter) Instagram
    Trending
    • How SpaceX wants to fuel Starship’s next phase with a Texas pipeline
    • In pictures: Venezuela earthquakes death toll surpasses 1,700 | Earthquakes News
    • Lewis Hamilton will be confident of challenging for victory at British GP, says his former team-mate Jenson Button | F1 News
    • Today on Sky Sports Racing: Brighton and Ffos Las host live action | Racing News
    • Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
    • I Found Jesus at a Drone Show
    • A different type of G7 central bank divergence
    • Private equity fund investors turn to debt-like deals in downturn
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

    adminBy adminJune 30, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 30, 2026Vulnerability / Enterprise Software

    Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

    A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.

    The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances.

    “Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments,” according to a description of the flaw in the NIST National Vulnerability Database (NVD). “Successful attacks of this vulnerability can result in the takeover of Oracle Payments.”

    The shortcoming impacts versions from 12.2.3 through 12.2.15. Patches for the flaw were shipped by Oracle as part of its Critical Security Patch Update last month.

    Cybersecurity

    CVE-2026-46817 has since come under active exploitation, with Defused Cyber noting on Monday that “over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots,” adding “this vulnerability has no known previous exploitation and no public PoC [proof-of-concept] code exists.”

    That said, there are currently no details available on how the security flaw is being exploited, who is behind them, and if it’s part of a broader opportunistic or targeted campaign aimed at unpatched systems.

    Late last year, another critical flaw in the same product (CVE-2025-61882, CVSS score: 9.8) was weaponized by threat actors linked to the Cl0p ransomware operation, with early attacks launched as far back as August 2025.

    Earlier this month, the company addressed a critical missing authentication zero-day vulnerability in PeopleSoft Suite (CVE-2026-35273, CVSS score: 9.8) that was actively exploited in ShinyHunters data theft and extortion attacks.

    Automaker Nissan has since acknowledged that it was among those impacted, stating it was the victim of a break-in that involved the exploitation of the PeopleSoft flaw, potentially exposing payroll records, bank details, Social Security numbers, and other personal and financial data belong to its employees in the U.S., Canada, Mexico, and Brazil.

    “What stood out was that CVE-2026-35273 isn’t just another trivial, easy-to-exploit single-request vulnerability,” Jake Knott, principal security researcher at watchTowr, said in a statement. “The attack chain is considerably more involved, combining multiple vulnerabilities to plant a malicious file that doesn’t execute immediately but waits until the server restarts.”

    “Where we would normally see simple bugs, this is a chain of multiple vulnerabilities, suggestive of a threat actor with genuine knowledge of and familiarity with the underlying codebase, and the ability to develop targeted capabilities against it.”

    Knott also pointed out that threat actors are exploiting vulnerabilities faster than ever before, urging organizations to  assume compromise and activate incident response processes to determine whether access was obtained before patches were applied, what was accessed, and whether persistence was established.

    Actively CVE202646817 EBusiness Exploited flaw Oracle Suite wild
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleI Found Jesus at a Drone Show
    Next Article Today on Sky Sports Racing: Brighton and Ffos Las host live action | Racing News
    admin
    • Website

    Related Posts

    Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

    June 30, 2026

    Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

    June 30, 2026

    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

    June 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    How SpaceX wants to fuel Starship’s next phase with a Texas pipeline

    In pictures: Venezuela earthquakes death toll surpasses 1,700 | Earthquakes News

    Lewis Hamilton will be confident of challenging for victory at British GP, says his former team-mate Jenson Button | F1 News

    Today on Sky Sports Racing: Brighton and Ffos Las host live action | Racing News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by