← Back

Wire · regulatory

Critical Oracle EBS bug added to CISA list of exploited vulnerabilities

Published

17 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at scworld.com

Verified

Fusion42 · 17 July 2026 · Fusion42 review

CISA added a critical Oracle EBS vulnerability (CVE-2026-46817, CVSS 9.8) to its exploited vulnerabilities list, requiring federal agencies to patch within three days. The flaw in Oracle Payments allows unauthenticated remote compromise and is already being actively exploited in the wild.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you sell to US federal agencies or manage their Oracle EBS systems, you have 72 hours to patch or face non-compliance with binding law. This vulnerability is already being exploited by attackers; delay means breach risk and regulatory penalty.

Coverage

1 source · 17 Jul 2026

Related on Wire

Topics

Cybersecurityoracle-ebscisa-bodpatch-deadlineactive-exploitationfederal-compliance