CISA Adds Two Known Exploited ... Note

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. These include CVE-2023-4346 affecting the KNX Protocol Connection Authorization Option 1 and CVE-2026-46817 in Oracle E-Business Suite. Exploited vulnerabilities are common attack methods posing significant risks to federal systems. Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive focuses on high-risk vulnerabilities on publicly exposed assets that grant full control after exploitation. BOD 26-04 also outlines requirements for agencies to check for compromises before applying patches. While the directive applies to federal civilian agencies, CISA recommends all organizations adopt a risk-based approach. CISA will continue to update the KEV Catalog with new exploited vulnerabilities. Organizations can nominate vulnerabilities for the KEV Catalog if they have a CVE ID, exploitation evidence, and mitigation steps.