U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-4346 | KNX Connection Authorization Option 1 Flaw Enables Permanent Device Lockout KNX Association KNX devices configured with Connection Authorization Option 1 can be locked out by an attacker because the BCU key (the device password) typically cannot be removed without entering the current password (CWE-645, an overly restrictive lockout mechanism). An attacker with access to the network used by the KNX installation can connect, purge all devices that lack additional security options, and set a BCU key; an attacker with physical access can do the same even on non-networked devices. The result is loss of availability: legitimate users are locked out of the device and often cannot reset it themselves (CVSS 7.5, availability impact only). Any deployment of KNX devices using the Connection Authorization Option 1 feature is affected; no specific firmware version ranges were published in the available data. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2026-07-15, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is unknown. Do: Per CISA's KEV listing and BOD 26-04 requirements, apply mitigations in line with vendor instructions: inventory KNX devices using Connection Authorization Option 1, restrict network access to KNXnet/IP interfaces and remote-access paths, and keep a documented copy of any BCU keys so devices can be unlocked. Review whether the connection authorization feature can be disabled or replaced with vendor-recommended more secure options; if mitigations are unavailable, follow BOD 26-04 guidance, including discontinuing use of internet-reachable KNX interfaces. | 7.5 | 1% | KEV |
| largelikely tens of thousands of KNX installations plausibly affected (a configuration-dependent subset of the multi-million-device KNX installed base) | |
| CVE-2026-46817 | Unauthenticated Takeover of Oracle Payments in Oracle E-Business Suite (CVE-2026-46817) Oracle E-Business Suite contains a critical improper privilege management flaw (CVE-2026-46817) in the File Transmission component of Oracle Payments, affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger it, with no credentials or user interaction required. Successful exploitation results in takeover of Oracle Payments, with high confidentiality, integrity, and availability impact (CVSS 3.1 9.8). Organizations running the affected E-Business Suite releases — especially those exposing the Payments/File Transmission interface to untrusted networks — are in scope. The issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-15, researchers have observed exploitation in the wild, and EPSS assigns a 13% probability of exploitation within 30 days (96th percentile). Do: Apply the remediation provided in Oracle's security advisory for CVE-2026-46817 to all Oracle E-Business Suite 12.2.3–12.2.15 environments running Oracle Payments, and in the meantime restrict HTTP/network access to the File Transmission component. Because the flaw is being actively exploited, review EBS/Payments access logs for unauthenticated requests and anomalous file-transmission activity to check for compromise. Federal agencies must apply mitigations in line with CISA BOD 26-04 timelines or discontinue use of the product if mitigations are unavailable. | 9.8 | 13% | KEV |
| moderate≈ several thousand installations (roughly 1k–10k Oracle EBS environments running Oracle Payments, with only a subset internet-reachable) |
Full article362 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog.
The flaws added to the catalog are:
- CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
- CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability
The vulnerability CVE-2023-4346 (CVSS score of 7.5) is an improper account lockout mechanism flaw affecting KNX devices that use KNX Connection Authorization Option 1. An attacker with access to the KNX network, or physical access to the device, can set a BCU key and lock the device, preventing legitimate users from resetting access. The issue can cause device availability loss and disrupt KNX installations.
KNX Connection Authorization Option 1 is a security mechanism in KNX building automation systems that controls access to devices by using a shared key (BCU key). It helps prevent unauthorized configuration changes, but weaker implementations can allow attackers to lock devices if they obtain network access.
The flaw CVE-2026-46817 affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable systems over HTTP. Oracle fixed the issue in last month’s Critical Patch Update and urges customers to apply the patches immediately. In early July, Defused Cyber researchers warned that this vulnerability is being actively exploited.
Defused Cyber did not disclose technical details about the attacks that exploited the flaw or the motivation of the attackers.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to urgently fix the Oracle flaw by July 18, 2026, and address the KNX Association KNX Protocol Connection Authorization Option 1 flaw by July 29, 2026
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195516/security/u-s-cisa-adds-knx-association-knx-protocol-connection-authorization-option-1-and-oracle-flaws-to-its-known-exploited-vulnerabilities-catalog.html