CISA has added CVE-2026-46817, a critical (CVSS 9.8) improper privilege management flaw in Oracle E-Business Suite, to its Known Exploited Vulnerabilities catalog, confirming active exploitation and setting a July 18, 2026 remediation deadline.
What Is It
CVE-2026-46817 is a vulnerability in the Oracle Payments product of Oracle E-Business Suite, specifically the File Transmission component. It is easily exploitable, allowing an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks can result in a complete takeover of Oracle Payments. The flaw is associated with three weakness types: improper privilege management (CWE-269), improper authentication (CWE-287), and missing authentication for a critical function (CWE-306).
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is network-exploitable with low complexity, requires no privileges or user interaction, and inflicts high impact on confidentiality, integrity, and availability. CISA's SSVC assessment rates exploitation as "active," automatability as "yes," and technical impact as "total." CISA added it to the KEV catalog on July 15, 2026, confirming active exploitation in the wild.
What's Vulnerable
Oracle E-Business Suite, Oracle Payments product (File Transmission component). Supported versions affected are 12.2.3 through 12.2.15. Known ransomware campaign use is listed as Unknown.
Patch Status
CISA requires organizations to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. The remediation due date is July 18, 2026. Vendor fixes are addressed in Oracle's May 2026 Critical Patch Update.