CISA Adds Actively Exploited Oracle E-Business Suite Takeover Flaw to KEV
ID: 8c4d5f89-ffb9-5113-85ec-c2e6d7a95a81
STIX ID: report--8c4d5f89-ffb9-5113-85ec-c2e6d7a95a81
Feed Name: Cyber Press
Threat Score
CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog after reports of active exploitation: an unauthenticated HTTP privilege-management flaw in Oracle E-Business Suite Payments that can allow full takeover of the Payments component, exposing financial transaction data and ERP integrations; organizations are urged to apply Oracle's patch immediately, audit internet-facing EBS instances, and perform forensic triage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
