CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
ID: 73260f5c-49c4-5983-ac01-848059262351
STIX ID: report--73260f5c-49c4-5983-ac01-848059262351
Feed Name: GBHackers
CISA warns that CVE-2026-46817, an improper privilege management and authentication vulnerability in Oracle E-Business Suite's Oracle Payments component, is being actively exploited in the wild; the flaw allows unauthenticated HTTP attackers to compromise Oracle Payments and potentially expose payment workflows, financial data, and connected systems. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog with an urgent remediation deadline for federal agencies, and organizations are advised to immediately identify affected instances, apply vendor fixes or mitigations, audit logs for suspicious activity, and restrict access while mitigation is implemented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
