A critical vulnerability, CVE-2026-4408, has been published with a CVSS score of 9.0, affecting Samba file servers and classic domain controllers that use the "check password script" feature. The…
CVE-2026-46817 (CVSS 9.8) — Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow
CVE. Sourced from nvd, summarised by Matproof.
AI Analysis
What changed and what to do.
A critical vulnerability has been published under CVE-2026-46817, affecting the Oracle Payments component of Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. The flaw, rated 9.8 out of 10 on the CVSS scale, resides in the File Transmission module and is easily exploitable over a network without requiring authentication. This means an unauthenticated attacker could potentially compromise the system remotely, leading to a complete loss of confidentiality, integrity, and availability.
Organizations that rely on Oracle E-Business Suite for financial operations, particularly those in the banking, insurance, and regulated payment processing sectors across the EU, are directly affected. Any entity using the Oracle Payments product for file-based transactions, such as payment file generation or transmission, should treat this as a high-priority risk. Given the severity and the nature of the vulnerability, it may also impact compliance with PSD2, GDPR, and other EU financial regulations that mandate robust security controls for payment data.
Compliance teams should immediately verify their Oracle E-Business Suite version and patch status. The next step is to apply the relevant security patch from Oracle’s Critical Patch Update as soon as possible. In the interim, consider implementing network-level restrictions to limit access to the affected component, and review audit logs for any signs of unauthorized activity. Finally, update your risk register and incident response plan to reflect this vulnerability, and ensure that any third-party vendors using this software are notified and required to patch.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More CVE updates
Latest in CVE.
A critical vulnerability has been published under CVE-2026-24444, affecting SDMC NE6037 cable modem routers running firmware versions 7.1.6.0.25 and 7.1.6.1.9_B9. The issue involves a hardcoded…
A critical vulnerability has been published under CVE-2026-34311, affecting Oracle Hospitality OPERA 5 Property Services, specifically versions 5.6.19.24, 5.6.22, and 5.6.25.19. The vulnerability…
A critical vulnerability has been published under CVE-2026-46775, affecting Oracle REST Data Services in versions 24.2.0 through 26.1.0. The flaw, rated 9.9 on the CVSS scale, is easily exploitable…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.