// Oracle HealthCRITICAL
CISA added CVE-2026-46817, a critical improper privilege management vulnerability in Oracle E-Business Suite's Oracle Payments component, to its Known Exploited Vulnerabilities catalog on July 15, 2026. The flaw allows unauthenticated attackers with HTTP network access to fully compromise Oracle Payments systems without authentication. Active exploitation has been confirmed in the wild. CISA ordered federal agencies to patch by July 18, 2026; Oracle issued fixes in its May 2026 Critical Security Patch Update.
- CISA orders feds to patch actively exploited Oracle flaw by Satu(opens in a new tab)
- CISA Warns of Actively Exploited Oracle E-Business Suite Flaw(opens in a new tab)
- CISA Warns of Oracle E-Business Suite Vulnerability Actively Exp(opens in a new tab)
- Critical Oracle EBS bug added to CISA list of exploited vulnerab(opens in a new tab)
- Cosmetics giant Estée Lauder victim of mass Oracle breach | Comp(opens in a new tab)
- Estée Lauder discloses data breach tied to Oracle E-Business Sui(opens in a new tab)
// Get alerts for Oracle Health