Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Threats and Vulnerabilities

Ransomware and the Ten Person Company

A single ransomware attack can disrupt your operations, lock you out of the tools you depend on, or expose sensitive data. Attackers are looking for weaknesses in software and services used by small firms, more than going after giant corporations or government agencies. Products such as cPanel, WordPress, and JetBrains TeamCity are being targeted, putting everyday business functions at risk.

What small business ransomware risks are real for companies like mine?

Ransomware attacks are rarely random. Attackers look for exposed, unpatched, or misconfigured software with known vulnerabilities. The CISA Known Exploited Vulnerabilities (KEV) Catalog, as of August 2026, lists 1,665 vulnerabilities, with 349 flagged for known ransomware campaign use. Among the entries added in 2026, several directly affect products your company may be using:

  • WebPros cPanel & WHM and WP2 (WordPress Squared): Missing authentication for critical functions (CVE-2026-41940) is confirmed as used in ransomware campaigns.
  • JetBrains TeamCity: A relative path traversal vulnerability (CVE-2024-27199) is likewise known to be used in ransomware attacks.
  • WordPress Core: Recent additions (CVE-2026-60137, CVE-2026-63030) have unknown ransomware use, but the popularity of WordPress makes it a frequent target.

If your business runs cPanel to manage web hosting, WordPress for its website, or TeamCity for software development, these are not theoretical risks. They are actively targeted entry points.

How do ransomware attackers actually get in?

Attackers do not need to find a new or sophisticated way in, they use what works. According to the KEV Catalog, several vulnerabilities added in 2026 that are known to be used in ransomware campaigns relate to missing authentication, code injection, and improper input validation. For example, cPanel and WordPress vulnerabilities often allow attackers to bypass login screens or run malicious code without any user credentials.

In real terms, this means that if you have not patched your cPanel, WordPress, or TeamCity instances, or if you have left default settings or outdated plugins in place, you are exposed to the same ransomware risk as any larger company running the same software.

Does small business ransomware matter for compliance?

If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as a defense contractor or subcontractor, ransomware risk is a technical issue, and it is also a compliance requirement. The Department of Defense enforces cybersecurity rules through DFARS 252.204-7012 and NIST SP 800-171 Rev 2. For many small businesses, this means you must meet either Level 1 (Foundational) or Level 2 (Advanced) requirements, depending on the type of information you handle.

Level 1 covers 17 practices focused on safeguarding FCI, while Level 2 requires implementing all 110 controls from NIST SP 800-171 Rev 2 to protect CUI. These controls include patch management, vulnerability scanning, secure configuration, and incident response, all directly relevant to ransomware defense.

What changed with CMMC and how does it affect small business ransomware risk?

As of July 2026, the Department of War suspended the CMMC Phase II third party certification requirement pending review. However, the underlying requirements remain in full force. You are still required to perform annual self assessments, post your score to SPRS, and have a senior official sign an annual affirmation. The government can still conduct its own assessments, and the senior official’s signature is now the primary assurance of compliance.

This means that if your self assessment ignores ransomware-exploited vulnerabilities in your environment, your company and its leadership face increased False Claims Act exposure, not less. There have been enforcement actions against companies that falsely certified compliance or failed to remediate known vulnerabilities. In one case, a contractor was cited for not scanning and remediating vulnerabilities as required. In another, a company failed to have a System Security Plan (SSP) on file and used non-compliant email systems. The liability can extend to primes, subcontractors, affiliates, and even private equity owners.

Which products should I focus on patching or securing first?

You cannot patch everything at once, but you can focus on what attackers are actually using. Based on the CISA Known Exploited Vulnerabilities Catalog, prioritize these if they are in your environment:

  • cPanel & WHM, WordPress: Patch for critical authentication and code execution vulnerabilities.
  • JetBrains TeamCity: Address known path traversal flaws.
  • Tomcat: While a recent Apache Tomcat vulnerability (CVE-2026-34486) was added to the catalog, ransomware use is unknown, but you should still review and patch if you use Tomcat.

For each, make sure you are:

  • Running supported versions.
  • Applying security updates promptly.
  • Disabling or removing unused plugins, themes, or modules.
  • Limiting internet exposure, do not leave admin interfaces open to the world unless necessary and protected.

What does the government actually check for small business ransomware readiness?

If you are in scope for NIST SP 800-171, you are expected to meet all requirements relevant to your systems and data. This includes:

  • Documenting your policies and procedures for patch management and incident response.
  • Maintaining evidence of vulnerability scans and patch application.
  • Providing scoping artifacts if requested, such as a CUI Flow Diagram and an Authorized User List.

Every control must be met in full. Documentation alone is not enough, real system-generated evidence is required. For Level 2, that means 110 controls and 320 assessment objectives.

Common questions

What is the CISA Known Exploited Vulnerabilities Catalog and why does it matter to my business? The CISA Known Exploited Vulnerabilities Catalog is a government-maintained list of vulnerabilities that are known to be exploited in the wild, including in ransomware campaigns. It helps you prioritize patching the vulnerabilities most likely to be targeted.

Is CMMC certification still required for small businesses right now? As of July 2026, the third party certification requirement is suspended, but self assessments, SPRS posting, and annual senior official affirmation remain mandatory for companies handling defense information.

What if I cannot patch a vulnerability right away? If you are required to meet NIST SP 800-171, you need to document any gaps in a Plan of Action & Milestones (POA&M), but all gaps must be actively managed and closed. The government expects real progress and evidence.

Prioritize Ransomware Defense Initiatives Now

If you work with defense contracts and need to meet NIST SP 800-171 or CMMC Level 2, start with a clear understanding of what is in your environment and what vulnerabilities apply. The Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services, covering all 110 NIST 800-171 controls for qualifying defense contractors. This can help you identify where you stand and what you need to fix, before ransomware finds you first. Learn more at cybergrantsalliance.org/cmmc-gap-assessment-grant/.

More on Threats

Threats · 4 min When Your IT Provider Is the Attack Path

Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.