Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

BOD 26-04, a fortnight of triage

2 min read
18:20UTC

CISA added six exploited CVEs in the first fortnight under BOD 26-04's triage model, and let the Splunk and Ubiquiti deadlines pass without naming anyone non-compliant.

TechnologyAssessed
Key takeaway

Six exploited flaws landed in a fortnight under BOD 26-04, with no agency named non-compliant yet.

Six actively exploited vulnerabilities reached CISA's KEV catalogue of Known Exploited Vulnerabilities across three updates in this fortnight, roughly 0.86 additions a day, under the risk-tiered BOD 26-04 that replaced the fixed-deadline BOD 22-01 on 10 June . The first-ever Splunk KEV deadline and the triple-CVSS-10 Ubiquiti listing both passed with no public CISA naming of a non-compliant agency. 1

CISA lists a CVE, the public identifier for a disclosed software flaw, only once active exploitation is confirmed. Additions have slowed only modestly under a directive built to let agencies triage rather than patch every entry on a fixed clock, and the proposed FY27 CISA budget cut has not visibly dented catalogue growth. Triage changed the obligation, not the threat. Absence of a compliance report is not proof of enforcement, nor of its failure; the new model's teeth stay untested until CISA names someone.

Whether three unrelated crews cashing in three unrelated flaws in one fortnight marks a closing window between disclosure and exploitation or ordinary churn will not be settled by a fortnight's data. The two dated arcs, FortiBleed to Lynx and BlueHammer to SYSTEM access, are what carry the point for now.

Deep Analysis

In plain English

CISA is the US government's cyber-security agency, and it keeps a public list of software flaws it knows criminals are actively using, ordering federal agencies to fix each one by a set deadline. This fortnight it added six such flaws across three updates, working out to roughly one every day and a bit. Two earlier deadlines, for flaws in Splunk software and Ubiquiti networking gear, passed during this period, but unlike under the old rules, CISA did not publicly say whether any agency missed them. The new system, called BOD 26-04, replaced an older rule that used to name agencies that missed deadlines; supporters say private tracking avoids handing criminals a list of slow-patching targets, critics say it removes the pressure that used to get things fixed.

Deep Analysis
Root Causes

BOD 26-04's risk-tiered model, which replaced BOD 22-01's flat two-week deadline on 10 June, lets CISA compress deadlines for the worst internet-facing bugs, three days for the SharePoint flaw this fortnight, while giving lower-risk vulnerabilities more remediation time. The 0.86-a-day addition rate is the tiering functioning as intended, not evidence of a slowdown.

CISA's decision not to publicly name any non-compliant agency after the Splunk and Ubiquiti deadlines passed reflects a policy choice made when BOD 26-04 replaced 22-01: public naming under the old directive was criticised internally as creating a target list for adversaries, so the new directive tracks compliance privately instead.

What could happen next?
  • Meaning

    CISA's move away from public non-compliance naming under BOD 26-04 removes an accountability mechanism BOD 22-01 relied on, with no public data yet available on whether private tracking achieves comparable patch speed.

  • Risk

    Without public naming, oversight bodies such as Congress or the Government Accountability Office lose an early public signal for which federal agencies are falling behind on the worst vulnerabilities.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

CISA· 4 Jul 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.