Wire · founder news, decoded · regulatory
Active Attacks on KNX Smart Building Protocol Leave Hardware Permanently Bricked
◆ Published
20 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
A five-year-old KNX smart building protocol vulnerability (CVE-2023-4346) allows attackers to permanently brick building automation hardware by setting an irreversible password lock and wiping device firmware. CISA added it to its Known Exploited Vulnerabilities catalog on 15 July 2026, triggering a federal mitigation deadline, but the flaw affects 172 countries and hundreds of millions of devices globally with no factory reset path available.
This Wire brief sits within Fusion42's coverage of Smart Buildings and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you're selling anything that plugs into or controls a KNX network — sensors, actuators, gateways, or integration software — your installed base is now a known target for permanent hardware destruction, and your customers have no way to recover. You need to ship a reset path or a network isolation product this month, or your support queue will become a liability.
◆ Related on Wire
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV17 July 2026
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV8 July 2026
- CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities17 July 2026
- Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)9 July 2026
- Rockwell Automation Flex 5000 Adapter16 July 2026
- CISA adds ColdFusion, Langflow, and Joomla bugs to known exploited vulnerabilities list9 July 2026
◆ Topics
Smart Buildings · Cybersecurity · knx-protocol · hardware-bricking · building-automation · zero-mitigation · supply-chain-vulnerability