Threat actors started exploiting CVE-2026-46817 (CVSS 9.8) in Oracle E-Business Suite Payments File Transmission. Defused observed first attacks on honeypots over the June 27-28, 2026 weekend. No public PoC exists. Oracle patched in May 2026 CSPU.