CISA Ditches Blanket Patching for Risk-Based Priority

CISA is shifting the job from patch everything fast to decide what truly deserves the next maintenance window. The old default treated every critical flaw as equal; the new model asks whether the asset is internet-exposed, tied to a known exploited vulnerability, or easy to automate at scale. The agency says a binding operational directive will change vulnerability management for federal agencies, with more specific guidance for critical infrastructure owners. That means the same patch can rise or fall in priority depending on where the system sits, and the burden of judgment moves to the owner’s own exposure and criticality model. If that scoring discipline is inconsistent, agencies and sectors will protect different things first and leave gaps between them.

Part of the PlainSec briefing for 2026-06-09

Sources