
CISA
US federal cyber lead; runs the KEV catalogue with mandatory federal patch deadlines.
CISA's Binding Operational Directive 26-04, effective 10 June 2026, replaced fixed KEV patch windows with a four-tier model; by 29 July, 34 of 39 new entries carried a three-day-or-less deadline against 12 of 31 before the change, even as the catalogue's own growth rate held near 0.78 entries a day throughout.
Last refreshed: 3 August 2026 · Appears in 1 active topic
How can CISA enforce its own KEV catalogue with 860 fewer staff?
Timeline for CISA
Published a 30 July alert telling water utilities to disconnect exposed controllers
Cybersecurity: Threats and Defences: Water plants told to unplug controllersMentioned in: The alert's citations predate the alert
Cybersecurity: Threats and DefencesCompressed federal KEV patch deadlines to a three-day median since June
Cybersecurity: Threats and Defences: KEV patch clocks fell to three daysCatalogued three new vulnerabilities across three vendors within ten days
Cybersecurity: Threats and Defences: Arista, Fortinet and Cisco flaws listedMentioned in: One firm hedged, heise online named APT28
Cybersecurity: Threats and DefencesBackground
The Cybersecurity and Infrastructure Security Agency is the US federal lead for protecting critical infrastructure and federal civilian networks. Created by Congress in 2018, it runs the Known Exploited Vulnerabilities catalogue, which issues mandatory patch deadlines for Federal Civilian Executive Branch agencies and voluntary urgency signals for private-sector organisations. The agency also leads the Joint Cyber Defence Collaborative, co-ordinates national counter-ransomware response, and provides election infrastructure security support to all fifty states. CISA operates within the Department of Homeland Security and works in formal partnership with the Five Eyes national CERTs, including the UK NCSC.
In the fortnight to 23 July, CISA led the fifteen-nation Coalition, co-sealed by the NSA and FBI, that published joint advisory AA26-204A; the advisory named Russian state actor LAUNDRY BEAR over a Zimbra webmail zero-click chain, and CISA's own contribution was pushing the technical indicators into its established KEV and alert channels so federal civilian agencies could check exposure without waiting for a separate FCEB bulletin.
The agency's expanding advisory workload sits against a proposed FY27 budget cut of roughly $707m and around 860 positions, a reduction that would fall on the same staff base maintaining the KEV catalogue's advisory quality and running joint international attributions.
Its new deadlines bite far harder
CISA issued Binding Operational Directive 26-04 on 10 June 2026, formally revoking BOD 22-01's fixed-window regime (14 days for non-critical, 2-7 days for critical) in favour of a four-dimension risk-tiered model assigning remediation windows of 3 days, 14 days, 60 days, or next upgrade cycle based on exploitability, exposure, asset criticality and known threat-actor behaviour. The catalogue stood at 1,656 entries at version 2026.07.29, adding entries at close to 0.78 a day, a pace essentially unchanged either side of the directive.
What changed is severity, not speed: of 39 entries added between 10 June and 29 July, 34 carried a remediation window of three days or less, 87 per cent, against 12 of 31 added between 1 May and 10 June, 39 per cent, and the median window fell from 14 days to three. Enforcement still lags in places: an actively-exploited Fortinet FortiSandbox flaw reached the KEV list a full month behind private detection, and Microsoft SharePoint logged its third deserialisation-flaw listing in three weeks by 22 July, evidence the tiering change has sharpened deadlines without yet closing the detection-to-listing gap.
Its own warning becomes a live incident
CISA assessed as early as February 2026 that China-linked Volt Typhoon had planted footholds in US power, water, transport and communications networks, prepositioning for disruption rather than espionage, distinct from Salt Typhoon's telecoms-focused spying campaign, which by then had affected at least 200 companies across 80 countries.
That prepositioning warning turned concrete on 30 July, when CISA published an alert reporting a sharp rise in attackers reaching internet-exposed programmable logic controllers at water and wastewater plants of every size, changing device passwords to lock operators out; CISA said the activity had already triggered boil water notices and forced sustained manual operation. Its instruction to operators was to disconnect exposed controllers rather than patch them, a response that treats the exposure itself, not a fixable flaw, as the danger.