
ON 15 July 2026 the U.S. Cybersecurity and Infrastructure Security Agency added two vulnerabilities to its Known Exploited Vulnerabilities catalogue.
The additions include a flaw in the KNX protocol and a critical issue in Oracle E‑Business Suite (CISA alert).
The KNX vulnerability tracked as CVE-2023-4346 has a CVSS score of 7.5 and stems from an overly restrictive account lockout mechanism in the Connection Authorisation Option 1.
Exploitation can lead to denial of service by locking devices and wiping configuration data.
Oracle’s flaw recorded as CVE-2026-46817 carries a CVSS score of 9.8 and allows an unauthenticated attacker to gain full control of Oracle Payments over HTTP.
Oracle has released a patch in the May 2026 Critical Update that addresses the issue.
Threat researchers have observed active exploitation of the Oracle flaw, with around nine hundred fifty exposed systems identified on the internet.
The KNX issue was added to the catalogue after evidence of real world use emerged (SecurityAffairs report).
Federal agencies must apply the Oracle patch from the May 2026 Critical Update by 18 July 2026.
They must also ensure KNX devices are updated or isolated before the 29 July 2026 deadline to avoid denial of service or potential takeover.
Defenders should review their asset inventories, disable any unnecessary KNX interfaces and segment operational technology networks.
They should also monitor for unusual lockout events and check the CISA KEV catalogue for future updates (CISA KEV).