Threat reportVulnerabilityTL-2026-1073

CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances

criticalACTIVE

CVE-2026-46817 (TL-2026-1073) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-02 and last reviewed 2026-07-16. It has no confirmed attribution, affects Oracle Oracle E-Business Suite - Oracle Payments (File Transmission, references 1 CVE (CVE-2026-46817), maps to 25 MITRE ATT&CK techniques (T1005, T1068, T1082), and is covered by 9 detection rules and 19 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-1073

Threat ID
TL-2026-1073
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
finance, supply-chain, human-resources, manufacturing, retail, government administration, back-office-operations
Target regions
North America, Europe, Asia, 005 - South America, Africa, Oceania
Detection rules
9
Indicators of compromise
19
Updates
2026-07-16 · revalidated 1× · latest source

How CVE-2026-46817 works

A critical (CVSS 9.8) unauthenticated remote takeover flaw in the File Transmission component of Oracle Payments (Oracle E-Business Suite 12.2.3-12.2.15) is under active in-the-wild exploitation. Honeypot telemetry from Defused captured crafted XML DeliveryRequest payloads against the /OA_HTML/ibytransmit endpoint attempting to read /etc/passwd, while Shadowserver and Validin identified roughly 950 internet-exposed EBS instances via enhanced IP- and domain-based fingerprinting.

CVE-2026-46817 is an improper privilege management / missing authentication for a critical function vulnerability (CWE-306, CWE-287) in the File Transmission sub-component of the Oracle Payments product within Oracle E-Business Suite (EBS). It affects EBS versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Payments (confidentiality, integrity, and availability) with low attack complexity and no user interaction, via crafted requests to the iPayment file transmission endpoint /OA_HTML/ibytransmit.

Oracle patched the vulnerability in its May 2026 Critical Security Patch Update (CSPU), released May 28, 2026, with a supplementary June 2026 CSPU released June 16, 2026. On June 27-28, 2026 -- roughly four weeks after the patch and before any public proof-of-concept existed -- threat-intelligence firm Defused observed the first in-the-wild exploitation attempts on its Oracle EBS honeypot infrastructure. The captured traffic consisted of POST requests to /OA_HTML/ibytransmit carrying a crafted XML DeliveryRequest payload using the CODEX_PULL transmission scheme, with the FULL_FILE_PATH parameter set to /etc/passwd -- a classic local file read / path traversal exploitation pattern used to exfiltrate sensitive server files (and potentially database credentials, encryption keys, or payment processor API keys from EBS configuration files). The observed source IP, 45.84.137.125, resolves to AS136787 (PacketHub S.A., France), though researchers assessed the attacker was routing traffic through a VPN/proxy to obscure true origin. Requests used the identifying User-Agent string ibytransmit-lab-poc/1.0 and targeted HTTPS/443.

Defused's broader monitoring recorded 456 exploitation attempts against monitored honeypots in a single 24-hour window (June 28, 2026), distributed globally: North America (193), Asia (181), Europe (53), South America (18), Africa (9), Oceania (2) -- indicating the activity had shifted from a single targeted proof-of-concept probe to broader opportunistic scanning within roughly 24 hours.

Separately, the Shadowserver Foundation, working with Validin LLC, enhanced its Oracle EBS internet-exposure fingerprinting by adding domain-based scanning to its existing IP-based fingerprinting methodology. This identified approximately 950 (reported as 'over 900') internet-accessible Oracle EBS instances globally, more than half based in the United States, representing organizations running finance, supply chain, HR, and back-office systems that are potentially vulnerable to CVE-2026-46817 if unpatched. Shadowserver published its findings via its public dashboard and social channels on July 1, 2026.

This incident follows a pattern of prior critical unauthenticated RCE flaws in Oracle EBS being weaponized rapidly after patch release -- most notably CVE-2025-61882, exploited by the Cl0p ransomware/extortion group in August 2025 for mass data-theft extortion campaigns against EBS customers. While no attribution to a named threat actor or group has been established for CVE-2026-46817 exploitation as of this report, the honeypot-observed activity progressing from a single targeted PoC-style probe to widespread scanning within a day is consistent with either a researcher/red-team validating exploitation feasibility or an early-stage opportunistic threat actor preparing for a larger campaign (potentially including ransomware/extortion operators who have previously targeted this exact product line).

MITRE ATT&CK techniques used in TL-2026-1073

Collection

T1005 Data from Local System; T1213 Data from Information Repositories; T1602 Data from Configuration Repository

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

command-and-control

T1090 Proxy

Persistence

T1136.001 Create Account: Local Account; T1505.003 Server Software Component: Web Shell

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

Impact

T1531 Account Access Removal; T1565.001 Data Manipulation: Stored Data Manipulation; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588.005 Obtain Capabilities: Exploits

Reconnaissance

T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in CVE-2026-46817

  • Oracle — Oracle E-Business Suite - Oracle Payments (File Transmission component)
    Vulnerable versions: 12.2.3; 12.2.4; 12.2.5; 12.2.6; 12.2.7; 12.2.8; 12.2.9; 12.2.10; 12.2.11; 12.2.12
    Fixed in: 12.2.3-12.2.15 with Oracle May 2026 Critical Patch Update applied

Remediation for CVE-2026-46817

Patches

  • Oracle E-Business Suite May 2026 Critical Patch Update (released 2026-05-28)
  • Oracle E-Business Suite June 2026 Critical Patch Update (supplementary, released 2026-06-16)

Immediate actions

  • Apply Oracle's May 2026 Critical Security Patch Update (CSPU) and the supplementary June 2026 CSPU to all Oracle E-Business Suite 12.2.3-12.2.15 instances immediately
  • Restrict internet exposure of Oracle EBS web interfaces, especially /OA_HTML/ paths, behind a VPN or zero-trust access gateway
  • Audit web/proxy server logs for POST requests to /OA_HTML/ibytransmit
  • Threat-hunt for the observed indicators: source IP 45.84.137.125, ASN AS136787 (PacketHub S.A.), and User-Agent string ibytransmit-lab-poc/1.0
  • Conduct a compromise assessment on any internet-exposed EBS instance that has not applied the May 2026 CSPU

Workarounds

  • Where immediate patching is not feasible, block or restrict access to /OA_HTML/ibytransmit at the reverse proxy/WAF layer
  • Remove Oracle EBS Payments/iPayment web interfaces from direct internet accessibility until patched

Longer-term hardening

  • Place all Oracle EBS deployments behind network segmentation and disallow direct internet exposure of application-tier endpoints
  • Deploy a WAF in front of Oracle EBS with rules to block anomalous XML DeliveryRequest / CODEX_PULL payloads
  • Rotate database credentials, encryption keys, and payment processor API keys stored in EBS configuration files if compromise is suspected
  • Establish continuous external-attack-surface monitoring for EBS/ERP internet exposure (as demonstrated by Shadowserver/Validin fingerprinting)

CVEs associated with CVE-2026-46817

CVE-2026-46817

Weaknesses (CWE) in CVE-2026-46817

CWE-306, CWE-287, CWE-284, CWE-269

Timeline of CVE-2026-46817

  • Oracle releases the May 2026 Critical Security Patch Update (CSPU) fixing CVE-2026-46817 in Oracle E-Business Suite Payments File Transmission component.
  • Oracle releases a supplementary June 2026 CSPU covering the same Oracle Payments/File Transmission area.
  • Defused observes the first in-the-wild exploitation attempt on Oracle EBS honeypots: a single unauthenticated file-read POST request to /OA_HTML/ibytransmit from IP 45.84.137.125 (AS136787 PacketHub S.A., France), targeting /etc/passwd via a CODEX_PULL XML DeliveryRequest payload.
  • Exploitation activity broadens from a single targeted proof-of-concept probe to widespread opportunistic scanning; Defused records 456 exploitation attempts against monitored honeypots in a 24-hour window, distributed globally (NA 193, Asia 181, Europe 53, South America 18, Africa 9, Oceania 2).
  • Security Affairs, Cyber Security News, and Secure Bulletin publish initial reports on active exploitation of CVE-2026-46817.
  • The Hacker News, Help Net Security, and additional outlets publish detailed technical writeups on the exploit mechanics and IOCs.
  • Shadowserver Foundation, working with Validin LLC, publishes findings identifying approximately 950 internet-exposed Oracle EBS instances using enhanced IP- and domain-based fingerprinting.
  • Cyber Security News republishes the Shadowserver/Validin exposure findings; article ingested into the Threadlinqs threat-intel pipeline as the hunt source for TL-2026-1073.
  • CISA adds CVE-2026-46817 to its Known Exploited Vulnerabilities (KEV) catalog, imposing a federal civilian agency remediation deadline of 2026-07-02 under Binding Operational Directive (BOD) 26-04.
  • CISA formally adds CVE-2026-46817 to its Known Exploited Vulnerabilities catalog, confirming active real-world exploitation and invoking Binding Operational Directive 26-04.
  • Deadline for U.S. Federal Civilian Executive Branch agencies to remediate CVE-2026-46817 per Binding Operational Directive 26-04.

Update history for TL-2026-1073

Sources cited for CVE-2026-46817

Detection coverage for TL-2026-1073

As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1073 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats