Executive Summary
On July 15, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2023-4346 and CVE-2026-46817. CVE-2023-4346 pertains to the KNX Protocol's overly restrictive account lockout mechanism, potentially allowing attackers to purge devices and set unauthorized keys. CVE-2026-46817 affects Oracle E-Business Suite's Payments component, enabling unauthenticated attackers to compromise the system via HTTP, leading to potential full system takeover. Both vulnerabilities pose significant risks to federal enterprises and have been actively exploited.
The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched systems. Organizations are urged to prioritize remediation efforts, especially for vulnerabilities known to be actively exploited, to mitigate potential breaches and maintain system integrity.
Why This Matters Now
The active exploitation of these vulnerabilities highlights the critical need for organizations to promptly address known security flaws. Delayed remediation can lead to severe consequences, including unauthorized access and system compromise.
Attack Path Analysis
An unauthenticated attacker exploited a vulnerability in Oracle E-Business Suite's Payments component to gain initial access. The attacker then escalated privileges within the system, moved laterally to other components, established command and control channels, exfiltrated sensitive financial data, and caused operational disruptions.
Kill Chain Progression
Initial Compromise
Description
An unauthenticated attacker exploited CVE-2026-46817 in Oracle E-Business Suite's Payments component via HTTP to gain unauthorized access.
Related CVEs
CVE-2023-4346
CVSS 7.5An overly restrictive account lockout mechanism in KNX Protocol Connection Authorization Option 1 allows attackers to purge all devices without additional security options enabled and set a BCU key.
Affected Products:
KNX Association KNX Protocol – Option 1
Exploit Status:
exploited in the wildCVE-2026-46817
CVSS 9.8An improper privilege management vulnerability in Oracle Payments allows unauthenticated attackers to compromise the system via HTTP, potentially leading to a complete takeover.
Affected Products:
Oracle E-Business Suite – 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, 12.2.15
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Local Accounts
Cloud Accounts
Default Accounts
Domain Accounts
Application Accounts
Service Accounts
Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities by installing applicable vendor-supplied security patches.
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face immediate KEV remediation requirements under BOD 26-04, with KNX protocol and Oracle E-Business Suite vulnerabilities threatening critical infrastructure operations.
Financial Services
Oracle E-Business Suite privilege management flaws and KNX protocol vulnerabilities expose banking systems to unauthorized access, requiring urgent Zero Trust segmentation implementation.
Health Care / Life Sciences
HIPAA compliance violations likely from KNX building automation and Oracle EBS patient data systems, demanding encrypted traffic controls and egress security enforcement.
Utilities
KNX protocol vulnerabilities in smart grid and building management systems enable lateral movement attacks, necessitating east-west traffic security and anomaly detection capabilities.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/Verified
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wildhttps://community.opentextcybersecurity.com/vulnerability-vault-228/oracle-e-business-suite-flaw-cve-2026-46817-actively-exploited-in-the-wild-364832Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be constrained by identity-aware policies, reducing unauthorized entry points.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely be limited by strict segmentation policies, reducing unauthorized access.
Control: East-West Traffic Security
Mitigation: Lateral movement would likely be restricted by east-west traffic controls, reducing unauthorized access to other components.
Control: Multicloud Visibility & Control
Mitigation: Command and control channels would likely be detected and disrupted, reducing persistent unauthorized access.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be blocked by egress policies, reducing unauthorized data transfer.
Operational disruptions would likely be limited to the initially compromised workload, reducing overall impact.
Impact at a Glance
Affected Business Functions
- Payment Processing
- Financial Reporting
- Supply Chain Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive financial data, including payment records and customer information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts of known vulnerabilities.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch systems to mitigate known vulnerabilities and reduce the attack surface.



