Robotics & Physical AIJul 15, 2026
Patch now: CISA flags an actively exploited Oracle E-Business Suite flaw that can take over Oracle Payments
CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on July 15: an improper-privilege-management flaw in Oracle E-Business Suite that lets an unauthenticated attacker over HTTP compromise Oracle Payments, with full module takeover possible. A KNX building-automation protocol flaw (CVE-2023-4346) was added the same day. KEV listing puts US federal agencies on a remediation deadline — everyone else should treat it as a patch-first list.
What it means If your company runs Oracle E-Business Suite — especially Payments — this is exploited in the wild and reachable without credentials; patch before the weekend.
Where it came from CISA