CISA | Alerts
Follow
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. These include CVE-2023-4346 affecting the KNX Protocol Connection Authorization Option 1 and CVE-2026-46817 in Oracle E-Business Suite. Exploited vulnerabilities are common attack methods posing significant risks to federal systems. Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive focuses on high-risk vulnerabilities on publicly exposed assets that grant full control after exploitation. BOD 26-04 also outlines requirements for agencies to check for compromises before applying patches. While the directive applies to federal civilian agencies, CISA recommends all organizations adopt a risk-based approach. CISA will continue to update the KEV Catalog with new exploited vulnerabilities. Organizations can nominate vulnerabilities for the KEV Catalog if they have a CVE ID, exploitation evidence, and mitigation steps.