Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember

Always First. Fast SOC News.

Did You Know

Response · WASHINGTON

Did You Know: Patching a KEV Host Before Collecting Evidence Can Erase the Intrusion Trail

September 25, 2026

By Noah Park, Response, New York

Did You Know text card: collect evidence before patching a KEV host.
SOCtember desk · text card

WASHINGTON - When CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog and flags forensic triage, the agency's Binding Operational Directive 26-04 implementation guidance tells responders to collect evidence before they patch. Patching first can destroy the artifacts that show whether an adversary already used the hole.

The guidance prioritizes volatile data within roughly the first day after a KEV addition. Volatile data includes memory, cache, and in-transit state that disappears when a host is rebooted or altered. CISA states that agencies should not alter or remediate systems prior to evidence and artifact collection when possible, and that critical patching should follow only after required evidence is collected, because patching may jeopardize artifact availability. Containment is likewise sequenced after initial collection, since premature isolation can wipe vital evidence and may alert an active operator.

For SOC and incident response desks, the operational lesson is order of operations, not slower patching. Scope the asset, preserve memory and related artifacts, then apply the critical patch and contain, and finish with triage analysis and an escalation decision. Treat a three-day KEV clock that also requires forensic triage as an evidence problem as well as a patch ticket.

Source: CISA BOD 26-04 Implementation Guidance for Prioritizing Security Updates Based on Risk, updated August 25, 2026.

Noah Park covers incident response and containment for SOCtember from New York.

Back to Response