cisaregulatorNewsThe Broadside1 min read

CISA adds CVE-2023-4346, CVE-2026-46817 to KEV catalog

BOD 26-04 makes high-risk KEV entries binding work on exposed federal assets, and contractors that run them inherit urgency.


TL;DR

CISA added CVE-2023-4346 in KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite to the Known Exploited Vulnerabilities (KEV) Catalog after evidence of active exploitation. Federal Civilian Executive Branch agencies must prioritize high-risk KEV flaws on publicly exposed assets that grant total control after exploitation under Binding Operational Directive (BOD) 26-04. Contractors and managed service providers that administer those systems inherit the urgency, but CISA’s alert does not list specific due dates for these two CVEs.

CISA adds CVE-2023-4346, CVE-2026-46817 to KEV catalog
Editorial illustration · drawn by The Broadside

CISA put two actively exploited vulnerabilities into the Known Exploited Vulnerabilities (KEV) Catalog: CVE-2023-4346 in the KNX Association KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite. The addition matters differently after Binding Operational Directive (BOD) 26-04. For Federal Civilian Executive Branch agencies, high-risk KEV entries on publicly exposed assets that give an attacker total control after exploitation become rapid-remediation priorities, with basic expectations to check whether threat actors compromised the system before the patch was applied. Contractors and managed service providers are not directly covered by BOD 26-04, but teams that manage federal systems inherit the customer’s obligation. CISA’s notice still leaves the operational question that matters most: the specific deadline for these two CVEs and whether timing changes by asset criticality. Federal teams should pull the BOD 26-04 tasking, verify exposure, and move confirmed exposure into the remediation queue.


Published ·Deep Fathom