Threat reportVulnerabilityTL-2026-1073
CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances
CVE-2026-46817 (TL-2026-1073) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-02 and last reviewed 2026-07-16. It has no confirmed attribution, affects Oracle Oracle E-Business Suite - Oracle Payments (File Transmission, references 1 CVE (CVE-2026-46817), maps to 25 MITRE ATT&CK techniques (T1005, T1068, T1082), and is covered by 9 detection rules and 19 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-1073
- Threat ID
- TL-2026-1073
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- finance, supply-chain, human-resources, manufacturing, retail, government administration, back-office-operations
- Target regions
- North America, Europe, Asia, 005 - South America, Africa, Oceania
- Detection rules
- 9
- Indicators of compromise
- 19
- Updates
- 2026-07-16 · revalidated 1× · latest source
How CVE-2026-46817 works
A critical (CVSS 9.8) unauthenticated remote takeover flaw in the File Transmission component of Oracle Payments (Oracle E-Business Suite 12.2.3-12.2.15) is under active in-the-wild exploitation. Honeypot telemetry from Defused captured crafted XML DeliveryRequest payloads against the /OA_HTML/ibytransmit endpoint attempting to read /etc/passwd, while Shadowserver and Validin identified roughly 950 internet-exposed EBS instances via enhanced IP- and domain-based fingerprinting.
CVE-2026-46817 is an improper privilege management / missing authentication for a critical function vulnerability (CWE-306, CWE-287) in the File Transmission sub-component of the Oracle Payments product within Oracle E-Business Suite (EBS). It affects EBS versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Payments (confidentiality, integrity, and availability) with low attack complexity and no user interaction, via crafted requests to the iPayment file transmission endpoint /OA_HTML/ibytransmit.
Oracle patched the vulnerability in its May 2026 Critical Security Patch Update (CSPU), released May 28, 2026, with a supplementary June 2026 CSPU released June 16, 2026. On June 27-28, 2026 -- roughly four weeks after the patch and before any public proof-of-concept existed -- threat-intelligence firm Defused observed the first in-the-wild exploitation attempts on its Oracle EBS honeypot infrastructure. The captured traffic consisted of POST requests to /OA_HTML/ibytransmit carrying a crafted XML DeliveryRequest payload using the CODEX_PULL transmission scheme, with the FULL_FILE_PATH parameter set to /etc/passwd -- a classic local file read / path traversal exploitation pattern used to exfiltrate sensitive server files (and potentially database credentials, encryption keys, or payment processor API keys from EBS configuration files). The observed source IP, 45.84.137.125, resolves to AS136787 (PacketHub S.A., France), though researchers assessed the attacker was routing traffic through a VPN/proxy to obscure true origin. Requests used the identifying User-Agent string ibytransmit-lab-poc/1.0 and targeted HTTPS/443.
Defused's broader monitoring recorded 456 exploitation attempts against monitored honeypots in a single 24-hour window (June 28, 2026), distributed globally: North America (193), Asia (181), Europe (53), South America (18), Africa (9), Oceania (2) -- indicating the activity had shifted from a single targeted proof-of-concept probe to broader opportunistic scanning within roughly 24 hours.
Separately, the Shadowserver Foundation, working with Validin LLC, enhanced its Oracle EBS internet-exposure fingerprinting by adding domain-based scanning to its existing IP-based fingerprinting methodology. This identified approximately 950 (reported as 'over 900') internet-accessible Oracle EBS instances globally, more than half based in the United States, representing organizations running finance, supply chain, HR, and back-office systems that are potentially vulnerable to CVE-2026-46817 if unpatched. Shadowserver published its findings via its public dashboard and social channels on July 1, 2026.
This incident follows a pattern of prior critical unauthenticated RCE flaws in Oracle EBS being weaponized rapidly after patch release -- most notably CVE-2025-61882, exploited by the Cl0p ransomware/extortion group in August 2025 for mass data-theft extortion campaigns against EBS customers. While no attribution to a named threat actor or group has been established for CVE-2026-46817 exploitation as of this report, the honeypot-observed activity progressing from a single targeted PoC-style probe to widespread scanning within a day is consistent with either a researcher/red-team validating exploitation feasibility or an early-stage opportunistic threat actor preparing for a larger campaign (potentially including ransomware/extortion operators who have previously targeted this exact product line).
MITRE ATT&CK techniques used in TL-2026-1073
Collection
T1005 Data from Local System; T1213 Data from Information Repositories; T1602 Data from Configuration Repository
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
command-and-control
Persistence
T1136.001 Create Account: Local Account; T1505.003 Server Software Component: Web Shell
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
Impact
T1531 Account Access Removal; T1565.001 Data Manipulation: Stored Data Manipulation; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588.005 Obtain Capabilities: Exploits
Reconnaissance
T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning
Affected products and versions in CVE-2026-46817
- Oracle — Oracle E-Business Suite - Oracle Payments (File Transmission component)
Vulnerable versions: 12.2.3; 12.2.4; 12.2.5; 12.2.6; 12.2.7; 12.2.8; 12.2.9; 12.2.10; 12.2.11; 12.2.12
Fixed in: 12.2.3-12.2.15 with Oracle May 2026 Critical Patch Update applied
Remediation for CVE-2026-46817
Patches
- Oracle E-Business Suite May 2026 Critical Patch Update (released 2026-05-28)
- Oracle E-Business Suite June 2026 Critical Patch Update (supplementary, released 2026-06-16)
Immediate actions
- Apply Oracle's May 2026 Critical Security Patch Update (CSPU) and the supplementary June 2026 CSPU to all Oracle E-Business Suite 12.2.3-12.2.15 instances immediately
- Restrict internet exposure of Oracle EBS web interfaces, especially /OA_HTML/ paths, behind a VPN or zero-trust access gateway
- Audit web/proxy server logs for POST requests to /OA_HTML/ibytransmit
- Threat-hunt for the observed indicators: source IP 45.84.137.125, ASN AS136787 (PacketHub S.A.), and User-Agent string ibytransmit-lab-poc/1.0
- Conduct a compromise assessment on any internet-exposed EBS instance that has not applied the May 2026 CSPU
Workarounds
- Where immediate patching is not feasible, block or restrict access to /OA_HTML/ibytransmit at the reverse proxy/WAF layer
- Remove Oracle EBS Payments/iPayment web interfaces from direct internet accessibility until patched
Longer-term hardening
- Place all Oracle EBS deployments behind network segmentation and disallow direct internet exposure of application-tier endpoints
- Deploy a WAF in front of Oracle EBS with rules to block anomalous XML DeliveryRequest / CODEX_PULL payloads
- Rotate database credentials, encryption keys, and payment processor API keys stored in EBS configuration files if compromise is suspected
- Establish continuous external-attack-surface monitoring for EBS/ERP internet exposure (as demonstrated by Shadowserver/Validin fingerprinting)
CVEs associated with CVE-2026-46817
Weaknesses (CWE) in CVE-2026-46817
Timeline of CVE-2026-46817
- Oracle releases the May 2026 Critical Security Patch Update (CSPU) fixing CVE-2026-46817 in Oracle E-Business Suite Payments File Transmission component.
- Oracle releases a supplementary June 2026 CSPU covering the same Oracle Payments/File Transmission area.
- Defused observes the first in-the-wild exploitation attempt on Oracle EBS honeypots: a single unauthenticated file-read POST request to /OA_HTML/ibytransmit from IP 45.84.137.125 (AS136787 PacketHub S.A., France), targeting /etc/passwd via a CODEX_PULL XML DeliveryRequest payload.
- Exploitation activity broadens from a single targeted proof-of-concept probe to widespread opportunistic scanning; Defused records 456 exploitation attempts against monitored honeypots in a 24-hour window, distributed globally (NA 193, Asia 181, Europe 53, South America 18, Africa 9, Oceania 2).
- Security Affairs, Cyber Security News, and Secure Bulletin publish initial reports on active exploitation of CVE-2026-46817.
- The Hacker News, Help Net Security, and additional outlets publish detailed technical writeups on the exploit mechanics and IOCs.
- Shadowserver Foundation, working with Validin LLC, publishes findings identifying approximately 950 internet-exposed Oracle EBS instances using enhanced IP- and domain-based fingerprinting.
- Cyber Security News republishes the Shadowserver/Validin exposure findings; article ingested into the Threadlinqs threat-intel pipeline as the hunt source for TL-2026-1073.
- CISA adds CVE-2026-46817 to its Known Exploited Vulnerabilities (KEV) catalog, imposing a federal civilian agency remediation deadline of 2026-07-02 under Binding Operational Directive (BOD) 26-04.
- CISA formally adds CVE-2026-46817 to its Known Exploited Vulnerabilities catalog, confirming active real-world exploitation and invoking Binding Operational Directive 26-04.
- Deadline for U.S. Federal Civilian Executive Branch agencies to remediate CVE-2026-46817 per Binding Operational Directive 26-04.
Update history for TL-2026-1073
- 2026-07-16 — CVE-2026-46817: Oracle E-Business Suite Payments File Transmission Flaw Under Active Exploitation, Added to CISA KEV: What changed No severity/exploitability/status escalation (already CRITICAL/ACTIVE). Corrected KEV timeline: existing record's 2026-07-02 'kev-added' entry is superseded/clarified by the confirmed CISA KEV addition on 2026-07-15 with a fede
Sources cited for CVE-2026-46817
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
- Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)
- Over 900 Oracle E-Business instances exposed to ongoing attacks
- Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
- Oracle EBS Flaw CVE-2026-46817 Exposes Oracle Payments to Takeover
- Critical flaw in Oracle E-Business Suite is under immediate threat
- Hackers Actively Exploit CVE-2026-46817 in Oracle E-Business Suite - 456 Attacks Recorded in 24 Hours
- Hackers Exploiting Critical Oracle E-Business Suite Vulnerability Actively in Attacks
- 900+ Oracle E-Business Suite Instances Exposed on the Internet
- Hackers now exploit critical Oracle E-Business flaw in attacks
- NVD - CVE-2026-46817
- Oracle Critical Patch Update Advisory - May 2026
- CVE-2026-46817 - active exploitation observed
Detection coverage for TL-2026-1073
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1073 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.