CISA KEV Catalog Addition: KNX Protocol Account Lockout Bypass and Oracle E-Business Suite Privilege Escalation
First seen Jul 16, 2026 · Updated Jul 16, 2026
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a KNX Protocol account lockout flaw (CVE-2023-4346) and an Oracle E-Business Suite improper privilege management vulnerability (CVE-2026-46817). Under BOD 26-04, FCEB agencies must prioritize remediation of these vulnerabilities on publicly exposed assets due to evidence of active in-the-wild exploitation.
Technical Analysis
CVE-2023-4346 affects the KNX Association's KNX Protocol Connection Authorization mechanism, where an overly restrictive account lockout implementation can be abused to facilitate unauthorized access or denial-of-service against building automation and industrial control systems using KNX. CVE-2026-46817 is an improper privilege management vulnerability in Oracle E-Business Suite, allowing an attacker to escalate privileges beyond intended access controls, potentially achieving broader control over ERP business logic and data. Both CVEs have confirmed evidence of active exploitation, meeting CISA's KEV inclusion criteria, and BOD 26-04 requires FCEB agencies to check for prior compromise before patching given the risk of total asset control post-exploitation. No public PoC, malware family, or specific exploitation chain details were provided in this advisory beyond the CVE identifiers and vulnerability classes. Organizations running AI agents or automation pipelines that integrate with Oracle E-Business Suite (e.g., agentic ERP data retrieval, RAG over business records, or agent-driven workflow automation) should treat privilege escalation on EBS hosts as a credential and data-exposure risk, since compromised EBS instances could leak API keys, service account credentials, or business data that agents consume downstream.
Affected Systems
KNX Association KNX Protocol implementations (Connection Authorization Option 1); Oracle E-Business Suite deployments with the affected privilege management component (specific version ranges per Oracle's security advisory for CVE-2026-46817)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in this advisory; refer to CISA KEV Catalog and vendor advisories for CVE-2023-4346 and CVE-2026-46817 for exploitation indicators.
Remediation Steps
- 1
Apply vendor patches
Apply the official patches/updates from KNX Association and Oracle addressing CVE-2023-4346 and CVE-2026-46817 respectively, following vendor security advisories.
- 2
Check for prior compromise
Per BOD 26-04, before or immediately after patching, review logs and forensic artifacts on affected internet-facing assets to determine whether compromise occurred prior to remediation.
- 3
Restrict public exposure
Limit or remove public internet exposure of KNX-enabled devices and Oracle E-Business Suite management interfaces; enforce network segmentation and VPN/MFA-gated access.
- 4
Prioritize based on KEV Catalog
Use CISA's KEV Catalog to prioritize remediation of these and other actively exploited vulnerabilities on publicly exposed assets granting full control post-exploitation.
- 5
Rotate credentials
For Oracle EBS instances, rotate service account and API credentials that may have been exposed, especially those used by integrated automation or agentic systems.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.