CRITICAL
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited
A critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817 (CVSS 9.8), is under active exploitation in the wild according to Defused Cyber. The flaw involves improper privilege management and authentication in the Oracle Payments module of E-Business Suite, allowing unauthenticated attackers to take over vulnerable instances. Organizations running Oracle E-Business Suite should apply patches and treat exposed instances as a priority.