
CISA Adds Actively Exploited Oracle E-Business Suite Takeover Flaw to KEV
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle E-Business Suite vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Tracked as CVE-2026-46817, the flaw is an improper privilege management vulnerability affecting Oracle E-Business Suite, specifically its Payments module. The vulnerability allows an unauthenticated attacker with HTTP […]
The post CISA Adds Actively Exploited Oracle E-Business Suite Takeover Flaw to KEV appeared first on Cyber Security News.