<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
    <channel>
        <title>Defused — under active exploitation</title>
        <link>https://defusedcyber.com/exploited</link>
        <description>In-the-wild exploitation reports from the Defused honeypot fleet.</description>
        
        <item>
            <title>CVE-2026-46817: Unauthenticated file read in Oracle E-Business Suite Payments</title>
            <link>https://defusedcyber.com/exploited/cve-2026-46817-oracle-e-business-suite</link>
            <guid>https://defusedcyber.com/exploited/cve-2026-46817-oracle-e-business-suite</guid>
            <pubDate>Sat, 27 Jun 2026 05:38:00 GMT</pubDate>
            <description>Our Oracle E-Business Suite decoys captured the first in-the-wild exploitation of CVE-2026-46817: six unauthenticated file-read attempts from a single source on 27 June 2026, roughly six weeks after Oracle’s May 2026 patch and before any public proof-of-concept existed.</description>
        </item>
    </channel>
</rss>