In 30 seconds
- If you run on-prem Microsoft SharePoint, treat this as a live fire event. CISA is warning about active exploitation and hardening is not optional.
- CISA is still adding actively exploited vulnerabilities to the KEV catalogue, which is basically a weekly list of what attackers are using right now.
- Fortinet FortiClient EMS has seen active exploitation of a critical issue, so any organisation with Fortinet management tooling should be checking versions and hotfix status.
Why it matters
If you are a regulated business in the Channel Islands, the uncomfortable truth is that most serious incidents still start with the boring stuff. An unpatched internet-facing system, a weak admin path, or a security control that exists on paper but not in reality.
The SharePoint angle matters because it is common in professional services and finance, and on-prem deployments tend to be long-lived and quietly exposed. When CISA puts out an alert telling organisations to harden, that is your signal that exploitation is not theoretical. This is exactly the kind of issue that turns into a breach investigation, client notifications, and awkward regulator conversations.
Then there is Fortinet again. FortiClient EMS, the endpoint management platform, has a critical vulnerability that is being actively exploited. If your organisation uses Fortinet management tooling, this is not a "check it next week" item. Confirm the exact version you are running and whether the latest hotfix has been applied.
CISA's KEV catalogue continues to grow. Four new entries one day, two more the next. Each one represents a vulnerability that is confirmed to be exploited in the wild. If you are not tracking KEV as a prioritisation tool, you are making patching decisions without the most useful signal available.
The practical play this week is simple. Assume anything internet-facing is being scanned constantly. Prioritise patches and mitigations for systems that can be reached from the outside, and do not let "we will do it next change window" become your incident report.
Questions to ask your team this week
- 1.Do we have any on-prem SharePoint servers, and are they internet-facing either directly or via a reverse proxy?
- 2.Are we tracking CISA KEV items, and do we have a defined SLA for patching anything that lands on that list?
- 3.Do we use Fortinet FortiClient EMS, and if yes, have we confirmed the exact version and applied the latest hotfixes?
- 4.If we had to take a core collaboration platform offline today, what is the business workaround for the next 48 hours?
One thing to do this week
Run a 30-minute "external exposure" check: list every internet-facing service you own (VPN, email security portals, SharePoint, remote access, vendor consoles), confirm who patches it, and confirm the last patch date. If you cannot answer those three things quickly, fix that first.
Sources
- CISA, "CISA Urges SharePoint Hardening After New Exploitations" (14 July 2026):
cisa.gov - Microsoft MSRC, CVE-2026-58644:
msrc.microsoft.com - CISA, "CISA Adds Four Known Exploited Vulnerabilities to Catalog" (14 July 2026):
cisa.gov - CISA, "CISA Adds Two Known Exploited Vulnerabilities to Catalog" (15 July 2026):
cisa.gov - CyberScoop, "Fortinet FortiClient EMS zero-day CVE-2026-35616":
cyberscoop.com - WatchTowr, "Fortinet FortiClient EMS Zero-Day Active Exploitation":
watchtowr.com - UK NCSC, "Ransomware-Resistant Backups":
ncsc.gov.uk

