On 15 July, CISA added a vulnerability in Oracle E-Business Suite to its KEV catalog - one that allows unauthenticated takeover of the payments module. The deadline for US federal agencies falls on 18 July. Three days. The same day, an older hole in the KNX building-automation protocol joined the list too.
- CISA added CVE-2026-46817 (Oracle E-Business Suite, Oracle Payments module) to the KEV on 15.07 - unauthenticated full takeover over the network.
- The deadline for US federal agencies is 18.07 - three days after the listing; if there's no patch, CISA says to take the product offline.
- The same day, CVE-2023-4346 (KNX building-automation protocol) was added too, with confirmed active exploitation.
Oracle E-Business Suite holds the accounting, orders and payments for large organizations. Exactly the kind of system you don't want opening up without a password. CISA says someone is doing it in the real world, which is why it's landed on the actively exploited list.
Here's the catch - the word is 'unauthenticated'. Not 'stolen account'. Not 'insider'. Anyone with network access to the interface can try it, no password needed. Put that on top of a system that moves money, and a CVSS 9.8 stops being an abstract number - it becomes someone else having access to your payments. The three-day deadline CISA gives isn't bureaucracy. It's a measure of how fast this kind of thing burns.
If you've got Oracle EBS exposed to the outside, the patch doesn't wait until next week. And the rule we keep repeating still stands: 'actively exploited' carries weight only because CISA says so, with a CVE number and a deadline attached. Anyone saying it without a number - that's a rumor.