Oracle
Vulnerabilities and patches across Oracle's enterprise stack — E-Business Suite (including Payments), Fusion Middleware, WebLogic Server, Database, and Java — driven by the January, April, July, and October Critical Patch Update cycle.
Oracle E-Business Suite Payments improper privilege management (unauth RCE)
A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle's May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.
Oracle E-Business Suite BI Publisher Integration unauth RCE
A critical authentication-bypass and remote-code-execution flaw in the BI Publisher Integration component of Oracle E-Business Suite (versions 12.2.3–12.2.14). Exploited in the wild by Cl0p since August 2025; linked to the Estée Lauder HR-system breach disclosed July 20, 2026.

Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell
Estée Lauder's July 20 letter says Cl0p breached its Oracle E-Business Suite HR system on August 9, 2025 via CVE-2025-61882. Dwell: 11 months.

CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands
CISA added CVE-2026-46817 to KEV on Wednesday: unauthenticated CVSS 9.8 takeover of Oracle E-Business Suite Payments. Oracle's May 2026 CPU already has the fix.