INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oracle E-Business Suite Flaw Exploited in Attacks

| 2026-06-30 05:04 CRITICAL LOW
Executive Summary AI-generated
The automotive industry is facing a critical security breach, with Nissan being among the companies impacted by a flaw in PeopleSoft software that exposed sensitive employee data. The vulnerability, CVE-2026-46817, was exploited by threat actors linked to the Cl0p ransomware operation, and has since been actively used in attacks on Oracle E-Business Suite and other systems. General Document Context suggests that this is not an isolated incident, with another critical flaw in the same product being weaponized by similar groups. The shortcoming impacts versions from 12.2.3 through 12.2.15, and patches were shipped as part of a Critical Security Patch Update last month. Organizations must assume compromise and activate incident response processes to determine whether access was obtained before patches were applied, what was accessed, and whether persistence was established.
Technical Mitigations AI-generated
* Implement a patch management strategy to ensure timely application of security patches for vulnerable systems, and consider using automated patch deployment tools. * Conduct regular vulnerability assessments and penetration testing (VSTs) to identify potential weaknesses in Oracle E-Business Suite and other enterprise software applications. * Educate users on the importance of keeping their operating systems and software up-to-date with the latest security patches, and provide training on how to properly configure and use these tools. * Consider implementing a "zero-trust" approach to network access, where all devices are assumed to be malicious unless proven otherwise, and require additional authentication and authorization mechanisms for remote access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-35273CVE-2026-35273 CVE-2024-21182CVE-2024-21182 CVE-2026-46817CVE-2026-46817 CVE-2025-61882CVE-2025-61882
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE
Incident Timeline
‎2025/06/30
Threat actors linked to the Cl0p ransomware operation exploited a previously unknown flaw in Oracle E-Business Suite.
tactic Ransomware
vulnerability CVE-2025-61882
organisation CVSS
organisation Cl0p
general_metric 9.8 year CVSS score
‎August 2025
Threat actors exploited a PeopleSoft Suite flaw, CVE-2026-35273.
tactic Ransomware
vulnerability CVE-2025-61882
organisation CVSS
organisation Cl0p
general_metric 9.8 year CVSS score
organisation Automaker Nissan
organisation PeopleSoft
organisation Social Security
organisation ShinyHunters
organisation Knott
‎early August 2025
The Clop extortion gang exploited a newly discovered vulnerability in the Oracle E-Business Suite, CVE-2025-61882.
vulnerability CVE-2025-61882
tactic Extortion
organisation Harvard University
organisation the University of Pennsylvania
organisation Dartmouth College
organisation the University of Phoenix
organisation Washington Post
organisation Logitech
organisation GlobalLogic
‎May 2026
Oracle released security updates to address the vulnerability with its May 2026 Critical Security Patch Update and urged customers to patch their systems immediately.
organisation Oracle
‎2026/05/31
Threat actors exploited CVE-2026-46817 in the wild using Patches provided by Oracle as part of its Critical Security Patch Update.
organisation Critical Security Patch Update
‎Jun 30, 2026
Threat actors used an exploit of CVE-2026-46817 in the wild to target Oracle Payments instances.
organisation Oracle Payments
organisation CVE-2026-46817
organisation Oracle E-Business
infrastructure 12.2.3
infrastructure 12.2.15
organisation the NIST National Vulnerability Database
organisation NVD
‎2026/06/30
Hackers have begun exploiting a critical Oracle E-Business Suite (EBS) financial application flaw, CVE-2026-46817.
organisation CVE-2026-35273
organisation ShinyHunter
organisation Vulnerability / Enterprise
organisation Oracle E-Business Suite
organisation Oracle EBS
organisation Defused
organisation Oracle Payments
organisation File Transmission
organisation EBS
organisation Oracle E-Business
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎12.2.3
Software Version
Metrics
infrastructure
‎12.2.15
Software Version
Intelligence Sources