VORANT. Threat Intelligence Sign in Get the full feed

CISA adds Oracle EBS and KNX vulnerabilities to KEV catalog

high vulnerability government-nationalfinancial-services

CISA has added CVE-2023-4346 (KNX Protocol authorization flaw) and CVE-2026-46817 (Oracle E-Business Suite privilege escalation) to its Known Exploited Vulnerabilities catalog based on active exploitation evidence.

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with two actively-exploited vulnerabilities that require immediate remediation attention. CVE-2023-4346 affects the KNX Protocol implementation and involves an overly restrictive account lockout mechanism that allows bypass of connection authorization controls. CVE-2026-46817 is an improper privilege management flaw in Oracle E-Business Suite that can lead to unauthorized privilege escalation.

These additions underscore CISA's commitment to maintaining the KEV Catalog as a prioritized remediation resource for the federal enterprise and beyond. Organizations should treat these vulnerabilities as high-priority, particularly on externally exposed systems, given the confirmed active exploitation. CISA's Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch agencies prioritize patching of KEV Catalog entries, and CISA encourages all organizations—regardless of sector—to adopt similar risk-based vulnerability management practices and check for potential prior compromise before applying patches.

Mentioned in this report

Vulnerabilities CVE-2023-4346KEVCVE-2026-46817KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free