Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

BOD 26-04, a fortnight of triage

2 min read
16:08UTC

CISA added six exploited CVEs in the first fortnight under BOD 26-04's triage model, and let the Splunk and Ubiquiti deadlines pass without naming anyone non-compliant.

TechnologyAssessed
Key takeaway

Six exploited flaws landed in a fortnight under BOD 26-04, with no agency named non-compliant yet.

Six actively exploited vulnerabilities reached CISA's KEV catalogue of Known Exploited Vulnerabilities across three updates in this fortnight, roughly 0.86 additions a day, under the risk-tiered BOD 26-04 that replaced the fixed-deadline BOD 22-01 on 10 June . The first-ever Splunk KEV deadline and the triple-CVSS-10 Ubiquiti listing both passed with no public CISA naming of a non-compliant agency. 1

CISA lists a CVE, the public identifier for a disclosed software flaw, only once active exploitation is confirmed. Additions have slowed only modestly under a directive built to let agencies triage rather than patch every entry on a fixed clock, and the proposed FY27 CISA budget cut has not visibly dented catalogue growth. Triage changed the obligation, not the threat. Absence of a compliance report is not proof of enforcement, nor of its failure; the new model's teeth stay untested until CISA names someone.

Whether three unrelated crews cashing in three unrelated flaws in one fortnight marks a closing window between disclosure and exploitation or ordinary churn will not be settled by a fortnight's data. The two dated arcs, FortiBleed to Lynx and BlueHammer to SYSTEM access, are what carry the point for now.

Deep Analysis

In plain English

CISA is the US government's cyber-security agency, and it keeps a public list of software flaws it knows criminals are actively using, ordering federal agencies to fix each one by a set deadline. This fortnight it added six such flaws across three updates, working out to roughly one every day and a bit. Two earlier deadlines, for flaws in Splunk software and Ubiquiti networking gear, passed during this period, but unlike under the old rules, CISA did not publicly say whether any agency missed them. The new system, called BOD 26-04, replaced an older rule that used to name agencies that missed deadlines; supporters say private tracking avoids handing criminals a list of slow-patching targets, critics say it removes the pressure that used to get things fixed.

Deep Analysis
Root Causes

BOD 26-04's risk-tiered model, which replaced BOD 22-01's flat two-week deadline on 10 June, lets CISA compress deadlines for the worst internet-facing bugs, three days for the SharePoint flaw this fortnight, while giving lower-risk vulnerabilities more remediation time. The 0.86-a-day addition rate is the tiering functioning as intended, not evidence of a slowdown.

CISA's decision not to publicly name any non-compliant agency after the Splunk and Ubiquiti deadlines passed reflects a policy choice made when BOD 26-04 replaced 22-01: public naming under the old directive was criticised internally as creating a target list for adversaries, so the new directive tracks compliance privately instead.

What could happen next?
  • Meaning

    CISA's move away from public non-compliance naming under BOD 26-04 removes an accountability mechanism BOD 22-01 relied on, with no public data yet available on whether private tracking achieves comparable patch speed.

  • Risk

    Without public naming, oversight bodies such as Congress or the Government Accountability Office lose an early public signal for which federal agencies are falling behind on the worst vulnerabilities.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

CISA· 4 Jul 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.