The September 28 CISA date is a remediation deadline for U.S. Federal Civilian Executive Branch agencies for the KEV-listed WordPress CVE-2026-87902 and SharePoint CVE-2026-65660. It is not, by itself, a statutory patch deadline for private organizations; for them, KEV listing is strong risk evidence supporting urgent remediation, board escalation, and possible contractual or insurance duties. CISA’s page shows the older BOD 22-01 as revoked, so agencies should apply the current directive and KEV instructions. I could not verify the current directive’s exact exception process from the available official text. Private organizations should not confuse missing September 28 with missing legal exposure: notification clocks generally arise from an actual incident—unauthorized access, data compromise, or operational impact—not merely from possessing a vulnerable product.
For Citrix, start the legal assessment upon evidence of unauthorized sessions, credential/token theft, configuration changes, lateral movement, or access to regulated data. For PeopleSoft, the reported x.jsp/u.jsp web shells, SIDEEYE, Neo-reGeorg, MeshAgent, or communications with 162.219.30[.]165 are compromise evidence—not merely vulnerability indicators—and should trigger immediate data-access and notification analysis. For SharePoint, web shells, malware, stolen IIS/machine keys, unauthorized document access, or persistence after patching do the same. For TeamCity, unauthorized administrator activity, altered builds, stolen secrets, malicious artifacts, downstream compromise, encryption, or extortion should initiate both incident-notification and SEC-materiality work. For an SEC registrant, materiality must be assessed without unreasonable delay and, if the incident is determined material, the Form 8-K deadline is four business days after that determination; I could not independently verify the current official SEC text in the evidence available here. Applicable personal-data, NIS2, or DORA clocks depend on the organization’s jurisdiction, sector, and facts, so I would not assign those deadlines without that scope information.
Tonight’s defensible step: create and time-stamp one counsel-reviewed decision record per affected product documenting asset/version, exposure, patch or isolation time, preserved logs and images, IOC queries and time range, confirmed or excluded access, data and business systems potentially affected, jurisdictions, notification/materiality trigger analysis, decision owner, and next review time. Record negative findings as “not found as of [time],” not “no compromise,” and preserve the evidence supporting that conclusion.