CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds Two Known Exploited Vulnerabilities to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2622

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-4346 affecting KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite. The agency emphasized that federal agencies must prioritize patching these vulnerabilities under Binding Operational Directive 26-04, and encouraged all organizations to adopt risk-based vulnerability management.

Why it matters: Federal agencies must immediately prioritize these vulnerabilities on internet-facing systems; all organizations should treat KEV Catalog entries as high-priority patches since active exploitation is confirmed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-4346 affecting KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite. The agency emphasized that federal agencies must prioritize patching these vulnerabilities under Binding Operational Directive 26-04, and encouraged all organizations to adopt risk-based vulnerability management.

Why it matters: Federal agencies must immediately prioritize these vulnerabilities on internet-facing systems; all organizations should treat KEV Catalog entries as high-priority patches since active exploitation is confirmed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary