• Sources: NVD CVE-2026-46817, CISA KEV catalog
  • Summary: CISA added CVE-2026-46817 to the Known Exploited Vulnerabilities catalog on 2026-07-15 (catalog version 2026.07.15, count 1644). The flaw is a missing-authentication issue (CWE-306, CWE-287, CWE-269) in the Oracle Payments File Transmission component of Oracle E-Business Suite 12.2.3 through 12.2.15, CVSS 9.8, exploitable over the network without authentication. Oracle addressed it in the CSPUMay2026 security alert. NVD moved its exploitation assessment from none to active on the KEV addition. The federal remediation due date is 2026-07-18.
  • Why it matters: Oracle E-Business Suite runs core finance and procurement for large enterprises, so an unauthenticated network-reachable flaw under active exploitation gives attackers direct access to that system.
  • Follow-up: Watch exploitation and ransomware reports and internet-exposure scans of unpatched EBS Payments deployments.

send feedback on this story