Oracle Payments Is Being Actively Exploited — No Public Playbook Required
Oracle E-Business Suite — enterprise software used by large organisations to manage finance, procurement, and operations — has a critical flaw in its Payments module that attackers are already exploiting, according to The Hacker News.
The vulnerability, CVE-2026-46817, carries a CVSS score of 9.8 (Critical). It allows anyone on a network to take full control of the Oracle Payments system without logging in first. Think of it like a bank vault where the lock mechanism responds to any key — including one the attacker made themselves five minutes ago.
What makes this notable is that no public proof-of-concept (a working demonstration of how the exploit works) exists. Researchers at Defused Cyber spotted the attacks over the weekend on systems set up specifically to attract attackers. Whoever is doing this worked it out independently.
Oracle issued a patch last month as part of its Critical Security Patch Update. That patch exists. The organisations being hit simply have not applied it.
This follows a pattern with Oracle's enterprise products. An earlier flaw in Oracle PeopleSoft Suite was exploited by the ShinyHunters group to steal employee records from Nissan — including payroll data, bank details, and Social Security numbers for workers across four countries.
What you should do: If your organisation runs Oracle E-Business Suite versions 12.2.3 through 12.2.15, confirm with your IT team that last month's Critical Security Patch Update has been applied. If you are unsure, assume it has not been and escalate today.
Sources

