CISA Gives Federal Agencies Three Days to Patch Critical Oracle Payments Flaw
A CVSS 9.8 vulnerability in Oracle E-Business Suite's Payments component, CVE-2026-46817, allows unauthenticated remote attackers to take full control of the payments module and manipulate financial transactions. CISA added it to the Known Exploited Vulnerabilities catalog on July 15, 2026, with a July 18 remediation deadline for federal agencies under the new BOD 26-04 framework, which introduced risk-tiered deadlines of 3, 14, or 60 days based on exploitation status and exposure. Approximately 950 Oracle EBS instances remain publicly exposed and potentially unpatched, and the same component was exploited by the Cl0p ransomware group in 2025, making unpatched organizations a known target profile.