CISA Adds Actively Exploited Oracle E-Business Suite Flaw to KEV
An improper privilege management vulnerability in Oracle E-Business Suite is currently being exploited in the wild, risking full takeover of Oracle Payments.
CISA has added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog, confirming that the flaw is being actively targeted. The vulnerability exists within Oracle E-Business Suite and stems from improper privilege management, categorized under CWE-269, CWE-287, and CWE-306. It allows unauthenticated attackers with network access via HTTP to compromise the Oracle Payments component.
Successful exploitation of this vulnerability can lead to a complete takeover of Oracle Payments. Federal agencies are required to apply vendor-provided mitigations by July 18, 2026, in accordance with CISA’s BOD 26-04. Organizations should evaluate their assets for internet exposure and strictly follow the mandated patching and forensics triage requirements to secure their environments.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.