logo

CISA Adds Actively Exploited Oracle E-Business Suite Takeover Flaw to KEV

ID: 8c4d5f89-ffb9-5113-85ec-c2e6d7a95a81

STIX ID: report--8c4d5f89-ffb9-5113-85ec-c2e6d7a95a81

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Tamilselvan

...
...

CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog after reports of active exploitation: an unauthenticated HTTP privilege-management flaw in Oracle E-Business Suite Payments that can allow full takeover of the Payments component, exposing financial transaction data and ERP integrations; organizations are urged to apply Oracle's patch immediately, audit internet-facing EBS instances, and perform forensic triage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.