BaltimoreCyber Brief
All briefs
24 August 2026·4 min read

Actively exploited vulnerabilities keep stacking up, and the bar for asset ownership just got higher

KEVEmergency PatchingOperational Resilience

In 30 seconds

  • Pick one KEV addition and treat it as a hard prioritisation signal. Patch or mitigate with evidence, not intent.
  • If you run Microsoft web apps, treat emergency ASP.NET patching as a reminder to tighten your update cadence and validate what is internet-facing.
  • If you have any operational technology, or suppliers who do, the Siemens S7 PLC advisory is a prompt to confirm segmentation, remote access controls, and incident response paths.

Why it matters

For regulated Channel Islands organisations, the risk is rarely just the CVE. It is the operational disruption, client impact, and regulator conversations that follow when an exposed service is compromised. This week's mix points to a simple theme: know what you run, know what is exposed, and patch what is being exploited.

TrueConf Server is a good example of "niche but real" enterprise software. It is the sort of thing that can sit quietly in an environment, sometimes managed by a third party, until it becomes the fastest way in. CISA ordering federal agencies to patch actively exploited TrueConf flaws is a strong signal. If it is in your estate, or your managed service provider's estate, it should jump the queue. If you have never heard of it, that is the point. The tools you forget about are the ones attackers remember.

The ASP.NET emergency patch story is a reminder that even well-run Microsoft estates can be caught out when fixes land outside the normal Patch Tuesday cycle. Microsoft releasing emergency security updates for a critical ASP.NET flaw means the risk was serious enough to break their own cadence. For organisations that rely on Microsoft web applications, whether customer-facing portals, internal tools, or API services, this is a "stop and check" moment. Confirm what is internet-facing, confirm the patch is applied, and confirm you have a process for handling out-of-band updates without waiting for the next change window.

Then there is the Siemens S7 PLC advisory. Many organisations assume operational technology is someone else's problem. But in practice, OT exposure is often indirect. Building management systems, HVAC controls, access control, and facilities infrastructure frequently rely on PLCs. If your building, your data centre, or a critical supplier uses Siemens controllers, the advisory matters. The question is not whether you have a factory floor. It is whether your supply chain or facilities do, and whether their remote access and segmentation controls are good enough to keep a compromise from reaching you.

The broader pattern this week is familiar but worth repeating. KEV additions are not background reading. Each one is a confirmed exploitation signal. If the affected product is in your environment, it moves to the front of the queue. The organisations that handle this well are the ones where someone owns each system, someone owns each patch decision, and someone can prove what happened afterwards. Evidence, not intent.

Questions to ask your team this week

  1. 1.Do we have an accurate inventory of externally reachable services, including "small" collaboration tools like TrueConf, and who owns patching for each one?
  2. 2.If an emergency Microsoft patch drops mid-cycle, what is our decision path, who approves, and how quickly can we deploy and verify?
  3. 3.Do we have any OT, building management, or facilities systems that rely on PLCs, and if not, which suppliers do, and how do they provide remote access?
  4. 4.Can we evidence patching or compensating controls for this week's KEV item within our change and risk process?

One thing to do this week

Run a 60-minute "exposure and ownership" drill: pull your list of internet-facing services, confirm the named technical owner for each, confirm the last patch date, and pick one item to validate end to end (patch applied, service restarted if needed, and evidence captured).

Sources

  • CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" (21 August 2026):
    cisa.gov
  • BleepingComputer, "CISA orders feds to patch actively exploited TrueConf Server flaws":
    bleepingcomputer.com
  • BleepingComputer, "Microsoft releases emergency security updates for critical ASP.NET flaw":
    bleepingcomputer.com
  • CISA, ICS Advisory AA26-231A (Siemens S7 PLC):
    cisa.gov

Want to discuss anything from this week's brief?

Join the conversation on LinkedIn