Skip to content

Warning: Multiple Vulnerabilities in Oracle Products, Patch Immediately!

Ccb.Belgium.Be May 29, 2026

Oracle released the May Critical Patch Update, a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. This update contains 35 new security patches across multiple product families. Please refer to the Oracle advisory to see which of your products are affected.

We want to highlight the following vulnerabilities due to their severity and potential impact.

CVE-2026-46840 affects the Backend-as-a-Service component of Oracle REST Data Services versions 24.2.0 through 26.1.0. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTPS, requiring no user interaction. Oracle has indicated a scope change, meaning exploitation can extend impact beyond the directly vulnerable product to other dependent systems. Successful exploitation results in full takeover of Oracle REST Data Services.

CVE-2026-46817 affects the File Transmission component of the Oracle Payments module within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no user interaction. Successful exploitation results in full takeover of Oracle Payments.

Patch The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.

Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion. In case of an intrusion, you can report an incident via: .

While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.