we_are_coded.by CODE · The world, decoded
БГ
CISA

A critical hole in Oracle E-Business Suite joins the actively exploited list

CISASecurity

On 15 July, CISA added a vulnerability in Oracle E-Business Suite to its KEV catalog - one that allows unauthenticated takeover of the payments module. The deadline for US federal agencies falls on 18 July. Three days. The same day, an older hole in the KNX building-automation protocol joined the list too.

In short
  • CISA added CVE-2026-46817 (Oracle E-Business Suite, Oracle Payments module) to the KEV on 15.07 - unauthenticated full takeover over the network.
  • The deadline for US federal agencies is 18.07 - three days after the listing; if there's no patch, CISA says to take the product offline.
  • The same day, CVE-2023-4346 (KNX building-automation protocol) was added too, with confirmed active exploitation.
Checked on16 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Oracle E-Business Suite holds the accounting, orders and payments for large organizations. Exactly the kind of system you don't want opening up without a password. CISA says someone is doing it in the real world, which is why it's landed on the actively exploited list.

The facts: on 15.07.2026, CISA added CVE-2026-46817 to the Known Exploited Vulnerabilities (KEV) catalog - improper access-control handling in Oracle E-Business Suite that lets an unauthenticated attacker with HTTP access compromise the Oracle Payments module, up to full system takeover. It's rated critical (9.8 per NVD). The deadline for US federal agencies is 18.07.2026; if no patch is available, CISA's guidance is to take the product offline. Reported affected versions are 12.2.3-12.2.15. The same day, CVE-2023-4346 also joined the KEV - a hole in the KNX building-automation protocol (CVSS 7.5) with confirmed active exploitation. Source: CISA Known Exploited Vulnerabilities Catalog; Oracle Critical Patch Update.

Here's the catch - the word is 'unauthenticated'. Not 'stolen account'. Not 'insider'. Anyone with network access to the interface can try it, no password needed. Put that on top of a system that moves money, and a CVSS 9.8 stops being an abstract number - it becomes someone else having access to your payments. The three-day deadline CISA gives isn't bureaucracy. It's a measure of how fast this kind of thing burns.

'Unauthenticated' means anyone with network access, no password required. That's why it's three days, not a month.

If you've got Oracle EBS exposed to the outside, the patch doesn't wait until next week. And the rule we keep repeating still stands: 'actively exploited' carries weight only because CISA says so, with a CVE number and a deadline attached. Anyone saying it without a number - that's a rumor.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog→Oracle - Critical Patch Update Advisory
Original: https://wearecoded.com/en/articles/cisa-kev-oracle-ebs-knx-0715.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news