// Alert

Oracle Health threat report

CISA added CVE-2026-46817, a critical improper privilege management vulnerability in Oracle E-Business Suite's Oracle Payments component, to its Known Exploited Vulnerabilities catalog on July 15, 2026. The flaw allows unauthenticated attackers with HTTP network access to fully compromise Oracle Payments systems without authentication. Active exploitation has been confirmed in the wild. CISA ordered federal agencies to patch by July 18, 2026; Oracle issued fixes in its May 2026 Critical Security Patch Update.

// Get alerts for Oracle Health