CISA Flags Actively Exploited Oracle E-Business Suite Vulnerability
An improper privilege management flaw in Oracle E-Business Suite is being actively exploited, potentially allowing unauthorized access to Oracle Payments.
CISA has added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog after confirming the flaw is being used in real-world attacks. The vulnerability exists within Oracle E-Business Suite due to improper privilege management, which allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments.
Successful exploitation of this flaw can result in a complete takeover of Oracle Payments. The vulnerability is tied to weakness types CWE-269, CWE-287, and CWE-306.
Federal agencies are required to apply vendor-provided mitigations by July 18, 2026, in accordance with CISA’s BOD 26-04. Organizations should evaluate their assets for internet exposure and follow all relevant patching and forensics triage guidance provided by CISA.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.