Skip to content
You can now search across every topic, entity and event.What's new
CISA
OrganisationUS

CISA

US federal cyber lead; runs the KEV catalogue with mandatory federal patch deadlines.

CISA's Binding Operational Directive 26-04, effective 10 June 2026, replaced fixed KEV patch windows with a four-tier model; by 29 July, 34 of 39 new entries carried a three-day-or-less deadline against 12 of 31 before the change, even as the catalogue's own growth rate held near 0.78 entries a day throughout.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

How can CISA enforce its own KEV catalogue with 860 fewer staff?

Timeline for CISA

#12 29 Jul

Published a 30 July alert telling water utilities to disconnect exposed controllers

Cybersecurity: Threats and Defences: Water plants told to unplug controllers
#12 29 Jul
#12 28 Jul

Compressed federal KEV patch deadlines to a three-day median since June

Cybersecurity: Threats and Defences: KEV patch clocks fell to three days
#12 28 Jul

Catalogued three new vulnerabilities across three vendors within ten days

Cybersecurity: Threats and Defences: Arista, Fortinet and Cisco flaws listed
#12 26 Jul
View full timeline →

Background

The Cybersecurity and Infrastructure Security Agency is the US federal lead for protecting critical infrastructure and federal civilian networks. Created by Congress in 2018, it runs the Known Exploited Vulnerabilities catalogue, which issues mandatory patch deadlines for Federal Civilian Executive Branch agencies and voluntary urgency signals for private-sector organisations. The agency also leads the Joint Cyber Defence Collaborative, co-ordinates national counter-ransomware response, and provides election infrastructure security support to all fifty states. CISA operates within the Department of Homeland Security and works in formal partnership with the Five Eyes national CERTs, including the UK NCSC.

In the fortnight to 23 July, CISA led the fifteen-nation Coalition, co-sealed by the NSA and FBI, that published joint advisory AA26-204A; the advisory named Russian state actor LAUNDRY BEAR over a Zimbra webmail zero-click chain, and CISA's own contribution was pushing the technical indicators into its established KEV and alert channels so federal civilian agencies could check exposure without waiting for a separate FCEB bulletin.

The agency's expanding advisory workload sits against a proposed FY27 budget cut of roughly $707m and around 860 positions, a reduction that would fall on the same staff base maintaining the KEV catalogue's advisory quality and running joint international attributions.

Key Issues
KEV deadlines

Its new deadlines bite far harder

CISA issued Binding Operational Directive 26-04 on 10 June 2026, formally revoking BOD 22-01's fixed-window regime (14 days for non-critical, 2-7 days for critical) in favour of a four-dimension risk-tiered model assigning remediation windows of 3 days, 14 days, 60 days, or next upgrade cycle based on exploitability, exposure, asset criticality and known threat-actor behaviour. The catalogue stood at 1,656 entries at version 2026.07.29, adding entries at close to 0.78 a day, a pace essentially unchanged either side of the directive.

What changed is severity, not speed: of 39 entries added between 10 June and 29 July, 34 carried a remediation window of three days or less, 87 per cent, against 12 of 31 added between 1 May and 10 June, 39 per cent, and the median window fell from 14 days to three. Enforcement still lags in places: an actively-exploited Fortinet FortiSandbox flaw reached the KEV list a full month behind private detection, and Microsoft SharePoint logged its third deserialisation-flaw listing in three weeks by 22 July, evidence the tiering change has sharpened deadlines without yet closing the detection-to-listing gap.

Critical infrastructure

Its own warning becomes a live incident

CISA assessed as early as February 2026 that China-linked Volt Typhoon had planted footholds in US power, water, transport and communications networks, prepositioning for disruption rather than espionage, distinct from Salt Typhoon's telecoms-focused spying campaign, which by then had affected at least 200 companies across 80 countries.

That prepositioning warning turned concrete on 30 July, when CISA published an alert reporting a sharp rise in attackers reaching internet-exposed programmable logic controllers at water and wastewater plants of every size, changing device passwords to lock operators out; CISA said the activity had already triggered boil water notices and forced sustained manual operation. Its instruction to operators was to disconnect exposed controllers rather than patch them, a response that treats the exposure itself, not a fixable flaw, as the danger.

Common Questions

Reference

What happens when a CISA patch deadline comes before the vendor fix?
In May 2026, CISA set a 9 May federal Deadline for CVE-2026-0300 in Palo Alto PAN-OS even though Palo Alto's own patches were not due until 13 May — the first documented case of a KEV Deadline preceding the vendor patch. Federal agencies must apply mitigations or remove the affected product from the network.Source: CISA KEV / Palo Alto advisory
What is the Joint Cyber Defence Collaborative?
The JCDC is CISA's public-private partnership structure for sharing threat intelligence and co-ordinating Incident Response between federal agencies, critical infrastructure operators, and technology companies.Source: CISA
What does CISA do for election security?
CISA provides election infrastructure security support to all fifty US states, including threat intelligence, vulnerability assessments, and Incident Response co-ordination.Source: CISA
Does CISA only cover federal networks or private companies too?
CISA has mandatory jurisdiction over Federal Civilian Executive Branch (FCEB) agencies. For the private sector, its KEV catalogue, advisories and incident-response support are voluntary — but carry strong compliance and reputational weight, particularly for critical infrastructure operators.Source: CISA
What is CISA's Known Exploited Vulnerabilities catalogue?
The KEV catalogue lists software vulnerabilities confirmed as actively exploited in the wild. Federal civilian agencies must patch within the stated Deadline; private organisations treat it as an urgent advisory signal.Source: CISA
What does CISA do and why does it matter?
CISA (Cybersecurity and Infrastructure Security Agency) is the US federal lead for critical infrastructure protection and civilian network security. It maintains the Known Exploited Vulnerabilities catalogue, co-ordinates ransomware Incident Response and provides threat intelligence to the private sector.
What is CISA's AA26-204A advisory about?
AA26-204A is a joint advisory CISA led with the NSA and FBI on 23 July 2026, co-sealed by 15 nations, naming Russian state actor LAUNDRY BEAR behind a zero-click exploit chain against Zimbra Collaboration Suite webmail.Source: CISA
Is CISA being cut under Trump's 2027 budget?
Trump's FY27 budget request proposes a $707m cut and the elimination of around 860 CISA positions, reducing the agency to roughly $2bn in operating budget.Source: event
How many vulnerabilities are in the CISA KEV catalogue?
The KEV catalogue held approximately 1,656 entries as of catalogue version 2026.07.29. Growth has slowed from the roughly two-a-day pace tracked through June to nearer 0.78 CVEs a day since BOD 26-04's risk-tiered triage took effect on 10 June 2026, with 87 per cent of entries added since carrying three-day remediation deadlines against 39 per cent before.Source: event
What is CISA BOD 26-04 and how does it change KEV patch deadlines?
BOD 26-04, issued 10 June 2026, revokes BOD 22-01 and replaces fixed 14-day/7-day KEV windows with a four-tier risk model: 3 days, 14 days, 60 days, or next upgrade cycle, based on exploitability, exposure, asset criticality, and threat actor behaviour.Source: CISA BOD 26-04
Source Material