CISA_KEV · JULY 2026 · CONFIRMED

Oracle E-Business Suite Vulnerability: Critical Threat to Oracle Payments

CVE-2026-46817Severity: HIGH

Oracle E-Business Suite has a confirmed critical vulnerability tracked as CVE-2026-46817, allowing unauthenticated attackers to compromise Oracle Payments.

What happened

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks can result in a complete takeover of Oracle Payments. This vulnerability is part of a series of critical flaws affecting various components of Oracle E-Business Suite, including Oracle Application Object Library, Oracle Work in Process, and Oracle Applications Framework. These vulnerabilities have CVSS scores ranging from 9.1 to 9.8, indicating a high severity level. Estée Lauder has already disclosed a data breach resulting from one of these flaws. The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch the actively exploited flaw by a specified deadline.

To assess your exposure, review the affected components and versions listed in the NVD entries for CVE-2026-60773, CVE-2026-60880, and CVE-2026-62546. If your systems are running any of the affected versions, immediate action is required. Monitor Oracle Payments for any unusual activity and apply patches as soon as they become available. Consult the primary sources for detailed information on the vulnerabilities and recommended actions.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If oracle e-business suite is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats