CVE-2026-46817Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 2.6 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
Federal remediation due Jul 18, 2026
1.0%
1.0% → 13%
2 GitHub repos
Added to the CISA catalog on Jul 15, 2026. Federal remediation due Jul 18, 2026. View catalog ↗
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
e-business_suite >= 12.2.3, <= 12.2.15Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60678High· 8.8Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)
CVE-2026-60810High· 8.2Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)
CVE-2026-87217Critical· 9.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2026-87128Critical· 9.1Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)
CVE-2026-83339Critical· 9.8Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)
CVE-2026-83202Critical· 9.1Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)