Briefing financecritical-infrastructure
CVE-2026-46817: Oracle EBS Payments RCE Under Active Exploitation — CISA KEV
CISA added CVE-2026-46817, a CVSS 9.8 unauthenticated RCE in Oracle E-Business Suite's Payments module, to the Known Exploited Vulnerabilities catalog on July 15, 2026. Exploitation began six weeks after the May patch, and approximately 950 instances remain exposed. Finance and government organisations running Oracle EBS are at immediate risk.