<- ALL CYBER NEWS

Critical

Oracle, E-Business Suite, CVE-2026-46817, CISA KEV, actively exploited, patch

Oracle E-Business Suite CVE-2026-46817 Under Active Attack

CVE-2026-46817, a CVSS 9.8 Oracle E-Business Suite flaw, is actively exploited and in CISA KEV with a July 18 deadline. Affects EBS 12.2.3-12.2.15.

CISA has ordered federal agencies to patch CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite, by Saturday 18 July. It is confirmed actively exploited. If you run Oracle EBS 12.2.3 through 12.2.15, treat this as a patch-today item.

What happened. CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on 15 July 2026 with a federal remediation deadline of 18 July. It is an improper privilege management flaw (CWE-269, CVSS 9.8 critical) in the Oracle Payments product of Oracle E-Business Suite, in the File Transmission component. Oracle lists supported affected versions as 12.2.3 through 12.2.15. It is easily exploitable over a network.

Which Oracle versions are affected?

Detail

Value

CVE

CVE-2026-46817

CVSS

9.8 (Critical), CWE-269 improper privilege management

Product

Oracle E-Business Suite - Oracle Payments (File Transmission)

Affected versions

12.2.3 - 12.2.15

CISA KEV added

2026-07-15

Federal deadline

2026-07-18

Who is affected. Organisations running self-hosted Oracle E-Business Suite in the 12.2.x line. EBS carries payments, financials, and supplier data, so this sits directly on the money path. The KEV deadline binds federal agencies, but exploitation does not check whether you are one.

What should you do about CVE-2026-46817?

Apply Oracle's patch now. If you cannot patch before the weekend, restrict network access to the Payments and File Transmission endpoints to trusted hosts only, and review logs for unexpected privilege changes or file-transmission activity. KEV listing means exploitation predates your patch window, so hunt backward as well as forward.

Is CVE-2026-46817 being exploited?

Yes. CISA only adds vulnerabilities to KEV after confirming active, real-world exploitation. Its EPSS probability sits near 1% (60th percentile), which is a useful reminder that EPSS lags confirmed exploitation - KEV is the stronger signal here.

Our read. A KEV entry is not a forecast, it is a confirmation that someone is already using this against real targets. In our analysis of the 2025 KEV catalog, 67% of vulnerabilities that were actually exploited would have been missed by an organisation relying on an annual penetration test to find them. A three-day federal deadline on an ERP flaw is what that gap looks like in practice: the only defence that moves at exploitation speed is continuous verification of what is actually exposed.

Reporting by BleepingComputer; vulnerability status per the CISA KEV catalog; severity and affected versions per NVD. Sources linked above.

Related: SAP NetWeaver CVSS 9.9 flaw and our KEV pentest analysis.

Frequently asked questions

Is CVE-2026-46817 being actively exploited?

Yes. CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on July 15, 2026, with a remediation deadline of July 18, 2026. It is unauthenticated and easily exploitable.

Which Oracle E-Business Suite versions are affected?

Oracle E-Business Suite 12.2.3 through 12.2.15, in the Oracle Payments product (File Transmission component).

What can an attacker do with CVE-2026-46817?

An unauthenticated attacker with network access over HTTP can compromise Oracle Payments (CVSS 9.8, CWE-269 improper privilege management), reaching exactly the financial and payment data an EBS deployment holds.

How do I fix CVE-2026-46817?

Apply Oracle’s security update immediately. Because it is in CISA KEV with a deadline that has already passed, also review logs for signs of prior exploitation and restrict internet exposure of the EBS instance.

Affected versions and references

  • Affected: Oracle E-Business Suite 12.2.3 through 12.2.15 (Oracle Payments, File Transmission component).

  • Fix: apply Oracle's security update immediately; the CISA KEV deadline (July 18, 2026) has passed.

References: NVD CVE-2026-46817 and the CISA KEV catalog.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.