Vulnerabilities · 95 days ago
Federal patch compliance is now a risk test, not a deadline queue. The fastest 3-day window goes to flaws on exposed assets that are in the KEV catalog, can be automated, and could give an attacker real control, and those cases also require forensic triage before patching can be counted as complete.
CISA’s BOD 26-04 replaces flat remediation timing with four factors: asset exposure, KEV status, exploit automation, and post-exploitation technical impact. Agencies also have to inventory and tag externally accessible assets, automate KEV status reporting, and update their vulnerability-management policies, so patch speed alone is no longer enough to prove compliance.
For federal teams, the gating issue becomes whether they can see what is exposed and tell if it was already compromised. That shifts vulnerability management toward asset discovery and evidence collection, not just faster ticket closure.
11 sources covering this story
CISA BOD 26-04: Requirements, Scope and Impact
CISA BOD 26-04 gives federal agencies new, risk-based requirements for vulnerability prioritization and remediation.
CISA orders federal agencies to "patch smarter" - Help Net Security
CISA has issued a Binding Operational Directive that will push US federal government agencies towards risk-based vulnerability management.
CISA Orders Agencies to Patch by Risk, Not Severity
New CISA directive tells federal agencies to patch by real-world risk, not CVSS severity scores
CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk
The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.
New CISA BOD 26-04 calls upon agencies to prioritize exploited vulnerabilities and assess compromise before patching.
CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice
A new CISA directive moves federal agencies beyond severity scores and toward a risk-based patching model that prioritizes real-world exploitation, asset exposure, and attacker impact — a framework many security leaders see as the future of vulnerability management.
How Federal Agencies Can Activate a Risk Operations Center (ROC) to Meet CISA BOD 26-04 | Qualys
Recognizing the ability of Frontier AI models to discover and exploit vulnerabilities at unprecedented speed and scale, CISA’s Binding Operational Directive (BOD) 26-04 marks a significant shift in…
CISA directive orders agencies to prioritize vulnerability patching in a new way
CISA has issued BOD 26-04, ordering federal agencies to prioritize software vulnerabilities using four new criteria to counter accelerating AI-driven threats.
CISA gives agencies new vulnerability remediation deadlines that take risk levels into account
The cybersecurity agency says it wants to help network defenders prioritize the fixes that matter the most.
VulnCheck provides automated SSVC decisions for federal and enterprise agencies to help address CISA BOD 26-04.
The Record from Recorded Future
CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says
A binding operational directive being released Wednesday will direct federal agencies to change the way they address vulnerabilities by elevating some while putting others to the side.
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
CISA is shifting federal agencies and critical infrastructure away from blanket patching toward targeted cyber risk prioritization, acting director Nick Andersen says.
Part of the PlainSec briefing for 2026-06-09