A critical security vulnerability in the Oracle E-Business Suite is currently being exploited by malicious actors. Tracked as CVE-2026-46817, the flaw resides in the File Transmission component of the Oracle Payments product. This vulnerability allows unauthenticated attackers with network access via HTTP to take over systems through low-complexity attacks. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
