CISA | Alerts

The website is for the Cybersecurity and Infrastructure Security Agency (CISA). CISA is a part of the U.S. Department of Homeland Security and is responsible for enhancing the security, resilience, and reliability of the nation's cyber and physical infrastructure. The agency plays a crucial role in protecting against cybersecurity threats, ensuring critical infrastructure is secure, and responding to cyber incidents. On the website, you can find information about various cybersecurity initiatives, resources for individuals and organizations to improve their cyber defenses, alerts and updates on emerging threats, and guidelines for incident response. The site also provides details on critical infrastructure sectors, partnerships, training programs, and opportunities to collaborate with CISA on security efforts.

Thread Of Notes

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with four new vulnerabilities, each showing signs of active exploitation. These additions include a double free vulnerability in Microsoft IKE Service Extensions and a weak authentication flaw in Microsoft SharePoint. Broadcom's VMware vCenter has a new path traversal vulnerability, and Apple macOS users face an improper authentication vulnerability. Such vulnerabilities are commonly targeted by cyber attackers and pose significant threats to federal systems.Binding Operational Directive (BOD) 26-04 mandates rigorous vulnerability management for Federal Civilian Executive Branch (FCEB) agencies. This directive emphasizes the critical role of the KEV Catalog in guiding remediation efforts. Federal agencies must quickly address high-risk vulnerabilities, particularly those in the KEV Catalog, especially on public-facing assets where exploitation could grant full control. The directive also sets expectations for agencies to check for system compromises before patching.Although BOD 26-04 specifically targets FCEB agencies, CISA strongly recommends that all organizations adopt a risk-based approach to vulnerability management. Prioritizing the remediation of KEV Catalog vulnerabilities is crucial for all entities. CISA will consistently add new vulnerabilities to the catalog if they meet the established criteria. Organizations aware of exploited vulnerabilities not yet listed in the KEV Catalog can nominate them for inclusion via CISA’s KEV Nomination Form. Nominated vulnerabilities must have a CVE ID, confirmed exploitation evidence, and clear mitigation advice.
CISA is warning of a rise in cyberattacks targeting programmable logic controllers (PLCs) within the Water and Wastewater Systems Sector. Threat actors are exploiting publicly exposed PLCs by changing passwords and IP addresses, leading to operational disruptions like boil water notices. These attacks affect water organizations of all sizes, even those with established cybersecurity measures. Exposed operational technology (OT) assets face increased risks of data manipulation, operational shutdowns, and even physical damage.CISA strongly advises disconnecting PLCs from the internet and utilizing VPNs or gateway devices for any necessary remote access. It is crucial to enable password protection and change all default passwords. IP allowlisting should be implemented to restrict remote access to known, trusted sources. After disconnecting, operators must ensure they have clean, verified backups of PLC configurations. For Rockwell Automation MicroLogix 1400 users, specific guidance is available to restore access lost due to password modifications.Secure remote access for OT systems can be achieved by following CISA's primary mitigations and the UK's National Cyber Security Centre's secure connectivity principles. Further assistance is available through the EPA's Cybersecurity Technical Assistance Program or a local CISA Regional Office. Cyber incidents should be reported to CISA's Operations Center or designated law enforcement agencies, providing specific details about the event.
CISA is aware of active exploitation of vulnerabilities in on-premises SharePoint Server instances, specifically CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, which enable cyber threat actors to gain unauthorized access. These vulnerabilities affect all supported on-premises SharePoint Server versions and involve establishing remote code execution and post-exploitation activities. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity. CISA urges organizations to detect and remediate potential compromises by implementing recommendations such as applying the latest patches and security updates from Microsoft. Additionally, CISA recommends verifying that Antimalware Scan Interface integration is enabled for each SharePoint web application and using specific AMSI and Microsoft Defender Antivirus detections. Organizations should also implement SharePoint Server hardening measures, including rotating IIS machine keys, establishing tailored logging mechanisms, and avoiding exposing SharePoint Servers directly to the internet. CISA added the vulnerabilities to its Known Exploited Vulnerabilities Catalog and urges users and administrators to review the Alert and apply necessary updates. The agency also recommends reporting incidents or anomalous activity to CISA via its 24/7 Operations Center. CISA may update this Alert to reflect new guidance issued by CISA or other parties, and the information in this report is being provided for informational purposes only. Overall, CISA's guidance aims to help organizations protect themselves against potential cyber threats by taking proactive measures to secure their SharePoint Server instances.