Threat ReportJuly 20, 2026
CVE-2026-46817: Inside the Oracle EBS Payments Takeover Flaw
A critical Oracle E-Business Suite flaw, CVE-2026-46817, is under active exploitation in the wild. The unauthenticated vulnerability targets Oracle Payments and carries a CVSS score of 9.8. Attackers began exploiting it roughly six weeks after Oracle's patch, before any public proof of concept existed. This report breaks down the attack chain, detection opportunities, and what security and compliance teams should do now.