The US Cybersecurity and Infrastructure Security Agency has added a flaw in KNX, one of the main open standards behind building automation, to its catalog of vulnerabilities that are actively being exploited. Federal civilian agencies were given until July 29 to fix it, and that deadline has now passed.
The bug is tracked as CVE-2023-4346 and carries a CVSS score of 7.5, rated high. It was first published back in 2023, but CISA only moved it into the Known Exploited Vulnerabilities catalog on July 15, 2026. That catalog is reserved for flaws the agency says it has reliable evidence of being used in real attacks, so the listing itself is the news here, not the age of the CVE.
What's affected
CISA's entry places the weakness in KNX Protocol Connection Authorization Option 1, and describes it as an overly restrictive account lockout mechanism. In the agency's own words, it could allow an attacker to purge all devices that do not have additional security options enabled, and to set a BCU key to lock the device.
That is the full extent of what has been published. The catalog entry does not say how an attacker reaches the flaw, what access they need first, or who has been exploiting it, and no vendor research write-up accompanies the listing. The KNX Association's own documentation and the NVD entry for the CVE carry what technical detail exists.
KNX is used widely in commercial and residential buildings to tie together systems such as lighting, heating and ventilation, which puts this one outside the usual run of enterprise software bugs. Recent additions to the same catalog have been dominated by conventional IT products, including an N-able N-central login bypass and a built-in password in Cisco's firewall management console.
How urgent is it
The two signals here point in different directions. EPSS, which estimates the chance a vulnerability gets exploited in the next 30 days, scores CVE-2023-4346 at about 0.9 percent, the 56th percentile, which is low. KEV inclusion, by contrast, reflects exploitation that has been observed rather than predicted, and it is the stronger signal of the two. CISA also marks the flaw as not known to be used in ransomware campaigns, which describes what has been seen so far and is not a guarantee about what comes next.
What you should do
Under Binding Operational Directive 22-01, federal civilian agencies must apply the vendor's mitigations or stop using the affected product, and that deadline has already lapsed. For everyone else, CISA's description singles out devices without additional security options enabled, so confirming those options are switched on across a KNX estate is the first check worth making, following the vendor's own hardening guidance. Standard practice for building automation applies as well: inventory what is deployed, and make sure KNX devices are not reachable from untrusted networks or the public internet.
No indicators of compromise have been published for this vulnerability.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.