Overview
Oracle Corporation provides enterprise database, ERP, and cloud software. Oracle E-Business Suite (EBS) — especially the Payments module — is a high-value target for threat actors due to internet-exposed HTTP interfaces and sensitive financial data.
Recent Developments
-
2026-09-15: larry-ellison canceled $7.5B rule-10b5-1 share sale plan; no shares sold (2026-09-13-larry-ellison-cancels-oracle-stock-sale)
-
2026-06-27: First in-the-wild exploitation of CVE-2026-46817 in EBS Oracle Payments (12.2.3–12.2.15) observed by defused-cyber on honeypots (2026-06-30-defused-oracle-cve-2026-46817-primary)
-
CVSS 9.8 unauthenticated HTTP flaw in File Transmission (
/OA_HTML/ibytransmit); enables Oracle Payments takeover -
Patched in May 2026 Critical Security Patch Update (CSPU); exploitation began ~6 weeks after patch
-
Context: follows CISA KEV listing of related Oracle PeopleSoft CVE-2026-35273 exploited by shinyhunters