Summary
Defused Cyber reported active in-the-wild exploitation of CVE-2026-46817 (CVSS 9.8) in Oracle E-Business Suite Oracle Payments (versions 12.2.3–12.2.15) over the June 28–29, 2026 weekend. The unauthenticated HTTP flaw allows full Oracle Payments takeover. Oracle patched it in the prior Critical Patch Update; no public PoC exists. Follows CISA KEV listing of related Oracle PeopleSoft CVE-2026-35273 exploited by ShinyHunters.
Source Analysis
Primary source: Security Affairs citing Defused Cyber, June 30, 2026. Active exploitation of enterprise ERP/payments stack.
PreScreening Notes
Score: 2 — Duplicate of an item already in the pipeline (pipeline/3-evaluated/2026-06-30-oracle-ebs-cve-2026-46817-active-exploitation.md). Same source URL and story; stale re-ingest left in 1-incoming/ after prior prescreening. Rejected to prevent parallel tracking.