Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

KEV patch clocks fell to three days

4 min read
16:08UTC

CISA gave federal agencies three days to patch a hard-coded password in Cisco's firewall console on 29 July. Recounting the catalogue shows 34 of the 39 entries added since 10 June carry a window that short.

TechnologyAssessed
Key takeaway

Recount the KEV due-date spread monthly; the published range no longer describes federal practice.

CISA gave federal agencies three days to patch Cisco Secure Firewall Management Center on 29 July, after adding a hard-coded password flaw in the console to its Known Exploited Vulnerabilities catalogue 1. CISA, the US Cybersecurity and Infrastructure Security Agency, maintains that catalogue as the list of flaws it has confirmed under active attack. The dates attached to each entry bind federal civilian agencies, and vulnerability-management Teams across the private sector inherit them through the scanning products that read the feed, without being bound by the directive at all.

That three-day window is no longer the exception. Of the 39 entries added between 10 June and 29 July, 34 carry a remediation deadline of three days or less, 87 per cent; of the 31 entries added between 1 May and 10 June, 12 did, 39 per cent 2. Every entry carrying both a dateAdded and a dueDate was counted, the gap measured in days, and the same arithmetic applied on both sides of 10 June, with entries lacking a dueDate excluded throughout. The median window fell from 14 days to three and the mean from 9.45 days to 4.41. The published range did not move, since both directives allow the same 3-to-14 spread, but the fortnight end of it has emptied: 58 per cent of the earlier entries allowed a fortnight or more, against 13 per cent of the later ones.

BOD 26-04 took effect on 10 June , replacing the fixed clocks of its predecessor with risk-tiered triage that assigns a window per entry rather than per class, and a security chief who read "risk-based" as room to breathe has been reading it backwards. Additions did not slow to match: entries reached the catalogue at roughly 0.78 per day on either side of the changeover, so what moved is the clock attached to a flaw, not the number of flaws attracting one 3. Bishop Fox's chained Ubiquiti UniFi OS Server flaws drew the same short window on 23 June , which read as an outlier at the time.

Seven weeks of register data cannot settle two confounds. If the newer entries skew towards edge appliances and management consoles, that class drew short clocks under the old regime as well, and composition alone could produce the whole drop; the catalogue has also gone quiet since 29 July, which reads equally as a summer lull in confirmed exploitation or as triage holding listings back. Both readings sat open when this beat first raised the doctrine-versus-composition question on 4 July , and only a monthly recount will close them.

Deep Analysis

In plain English

CISA is the US government's cyber-defence agency. It keeps a public list, the Known Exploited Vulnerabilities catalogue, of software flaws that hackers are already using in real attacks, and it tells federal agencies how fast they must fix each one. Until June, every flaw on the list got roughly the same countdown: about two weeks. Since then, CISA has switched to a system that scores how dangerous each flaw looks and hands out a much shorter deadline, sometimes as little as three days, to the ones it rates worst. The numbers now show that shorter deadline has become the norm rather than the exception: most new entries in the past seven weeks got the fastest possible clock.

Deep Analysis
Root Causes

CISA's risk-tiering formula scores four inputs: asset internet exposure, KEV status, exploit-automation feasibility and post-exploitation impact. Only the top tier draws sub-week deadlines; the rest fall into 14-day, 60-day or next-upgrade-cycle bands.

The compression is structurally possible only because BOD 26-04 replaced a single deadline field with four, giving CISA discretion to slot more flaws into the top band without amending the directive itself. Under BOD 22-01, moving a flaw's deadline meant a new directive or a public exception; under BOD 26-04, it is a scoring decision made inside the agency, invisible until the catalogue entry appears.

What could happen next?
  • Consequence

    Enterprise patch programmes that adopt CISA's tiering as a benchmark will face compressed prioritisation windows even outside the federal mandate.

  • Risk

    If the compression reflects catalogue composition rather than genuine escalation, organisations may over-index on speed for a shrinking pool of high-severity entries while missing the ones now parked in 60-day or next-upgrade-cycle tiers.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.