BaltimoreCyber Brief
All briefs
10 August 2026·4 min read

Exploited vulnerabilities are piling up, and the patching window just got shorter

Vulnerability ManagementPatch GovernanceMicrosoft

In 30 seconds

  • CISA added multiple actively exploited vulnerabilities to the KEV catalogue this week. Treat these as priority patch items, not background noise.
  • The UK NCSC reiterated urgent action for on-premises Microsoft SharePoint Server exploitation. If your SharePoint is internet-facing, assume heightened risk right now.
  • If you run Cisco SD-WAN, treat this as a board-level patching priority. Exploitation is confirmed and remediation windows are very short.

Why it matters

For regulated Channel Islands organisations, the practical risk this week is not theoretical. KEV additions and NCSC exploitation alerts are strong signals that attackers already have working tradecraft. They are not researching. They are operating.

The SharePoint story keeps running because the problem keeps running. NCSC has now issued specific guidance for UK organisations on active exploitation of on-premises SharePoint Server. If you are a financial services firm, a law practice, or a government body still running on-prem SharePoint, you need to treat this as a live incident response posture, not a scheduled maintenance task. Patch first, then validate. Check for persistence. Look for unexpected admin accounts, modified machine keys, or suspicious activity in your logs. Patching alone may not be enough if an attacker has already established a foothold.

Then there is Cisco SD-WAN. CISA has ordered all federal agencies to patch a critical vulnerability, and when CISA issues that kind of directive, it is because exploitation is confirmed and the blast radius is significant. For Channel Islands organisations using Cisco networking infrastructure, this is a board-level conversation. SD-WAN sits at the heart of how traffic flows between sites, to the cloud, and to remote users. A compromise here is not a single-system problem. It is a network-wide problem.

The broader pattern is clear. The KEV catalogue is growing faster than most organisations can patch. CISA added three vulnerabilities on 4 August and another on 5 August. Each one represents confirmed, active exploitation. The question is not whether these vulnerabilities are relevant to you. It is whether you have a process that can respond within days, not weeks.

The fastest win is disciplined asset ownership and patch execution, plus quick checks for exposure on internet-facing services. If you cannot patch immediately, you need compensating controls you can actually operate: restricting management interfaces, tightening conditional access, and increasing monitoring for suspicious admin activity. The organisations that handle this well are the ones where someone owns each system, someone owns each patch decision, and someone can prove what happened afterwards.

Questions to ask your team this week

  1. 1.Which internet-facing systems do we operate today, including legacy, and who is the named owner for patching each one?
  2. 2.Do we have any on-premises SharePoint Server instances, and are they reachable from the internet, directly or via reverse proxy?
  3. 3.Are we running Cisco SD-WAN, and can we confirm patch level and configuration hardening against the latest exploited issue?
  4. 4.What is our process for acting on KEV additions within 72 hours, including emergency change approval and after-hours patching?

One thing to do this week

Run a 30-minute exposure review: confirm whether SharePoint Server and Cisco SD-WAN are in your environment, then align patch plans to the latest KEV additions and document owners, deadlines, and verification steps.

Sources

  • CISA, "CISA Adds Three Known Exploited Vulnerabilities to Catalog" (4 August 2026):
    cisa.gov
  • CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" (5 August 2026):
    cisa.gov
  • UK NCSC, "Active exploitation of vulnerability affecting Microsoft Office SharePoint Server products in the UK":
    ncsc.gov.uk
  • The Record, "CISA orders all federal agencies to patch Cisco SD-WAN bug":
    therecord.media

Want to discuss anything from this week's brief?

Join the conversation on LinkedIn