CISA adds Oracle EBS and KNX vulnerabilities to KEV catalog
CISA has added CVE-2023-4346 (KNX Protocol authorization flaw) and CVE-2026-46817 (Oracle E-Business Suite privilege escalation) to its Known Exploited Vulnerabilities catalog based on active exploitation evidence.
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with two actively-exploited vulnerabilities that require immediate remediation attention. CVE-2023-4346 affects the KNX Protocol implementation and involves an overly restrictive account lockout mechanism that allows bypass of connection authorization controls. CVE-2026-46817 is an improper privilege management flaw in Oracle E-Business Suite that can lead to unauthorized privilege escalation.
These additions underscore CISA's commitment to maintaining the KEV Catalog as a prioritized remediation resource for the federal enterprise and beyond. Organizations should treat these vulnerabilities as high-priority, particularly on externally exposed systems, given the confirmed active exploitation. CISA's Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch agencies prioritize patching of KEV Catalog entries, and CISA encourages all organizations—regardless of sector—to adopt similar risk-based vulnerability management practices and check for potential prior compromise before applying patches.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free