cisaregulatorNewsThe Broadside1 min read

CISA adds CVE-2023-4346, CVE-2026-46817 to KEV catalog

BOD 26-04 makes high-risk KEV entries binding work on exposed federal assets, and contractors that run them inherit urgency.


TL;DR

CISA added CVE-2023-4346 in KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite to the Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation. Federal Civilian Executive Branch agencies must prioritize high-risk KEV flaws on publicly exposed assets that grant total control after exploitation under Binding Operational Directive (BOD) 26-04. Contractors and managed service providers that administer those systems inherit the urgency, but CISA’s alert does not list specific due dates for these two CVEs.

CISA put two actively exploited vulnerabilities into the Known Exploited Vulnerabilities (KEV) Catalog: CVE-2023-4346 in the KNX Association KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite. The addition matters differently after Binding Operational Directive (BOD) 26-04. For Federal Civilian Executive Branch agencies, high-risk KEV entries on publicly exposed assets that give an attacker total control after exploitation become rapid-remediation priorities, with basic expectations to check whether threat actors compromised the system before the patch was applied. Contractors and managed service providers are not directly covered by BOD 26-04, but teams that manage federal systems inherit the customer’s obligation. CISA’s notice still leaves the operational question that matters most: the specific deadline for these two CVEs and whether timing changes by asset criticality. Federal teams should pull the BOD 26-04 tasking, verify exposure, and move confirmed exposure into the remediation queue.


Published ·Deep Fathom