Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

BOD 26-04, a fortnight of triage

2 min read
12:09UTC

CISA added six exploited CVEs in the first fortnight under BOD 26-04's triage model, and let the Splunk and Ubiquiti deadlines pass without naming anyone non-compliant.

TechnologyAssessed
Key takeaway

Six exploited flaws landed in a fortnight under BOD 26-04, with no agency named non-compliant yet.

Six actively exploited vulnerabilities reached CISA's KEV catalogue of Known Exploited Vulnerabilities across three updates in this fortnight, roughly 0.86 additions a day, under the risk-tiered BOD 26-04 that replaced the fixed-deadline BOD 22-01 on 10 June . The first-ever Splunk KEV deadline and the triple-CVSS-10 Ubiquiti listing both passed with no public CISA naming of a non-compliant agency. 1

CISA lists a CVE, the public identifier for a disclosed software flaw, only once active exploitation is confirmed. Additions have slowed only modestly under a directive built to let agencies triage rather than patch every entry on a fixed clock, and the proposed FY27 CISA budget cut has not visibly dented catalogue growth. Triage changed the obligation, not the threat. Absence of a compliance report is not proof of enforcement, nor of its failure; the new model's teeth stay untested until CISA names someone.

Whether three unrelated crews cashing in three unrelated flaws in one fortnight marks a closing window between disclosure and exploitation or ordinary churn will not be settled by a fortnight's data. The two dated arcs, FortiBleed to Lynx and BlueHammer to SYSTEM access, are what carry the point for now.

Deep Analysis

In plain English

CISA is the US government's cyber-security agency, and it keeps a public list of software flaws it knows criminals are actively using, ordering federal agencies to fix each one by a set deadline. This fortnight it added six such flaws across three updates, working out to roughly one every day and a bit. Two earlier deadlines, for flaws in Splunk software and Ubiquiti networking gear, passed during this period, but unlike under the old rules, CISA did not publicly say whether any agency missed them. The new system, called BOD 26-04, replaced an older rule that used to name agencies that missed deadlines; supporters say private tracking avoids handing criminals a list of slow-patching targets, critics say it removes the pressure that used to get things fixed.

Deep Analysis
Root Causes

BOD 26-04's risk-tiered model, which replaced BOD 22-01's flat two-week deadline on 10 June, lets CISA compress deadlines for the worst internet-facing bugs, three days for the SharePoint flaw this fortnight, while giving lower-risk vulnerabilities more remediation time. The 0.86-a-day addition rate is the tiering functioning as intended, not evidence of a slowdown.

CISA's decision not to publicly name any non-compliant agency after the Splunk and Ubiquiti deadlines passed reflects a policy choice made when BOD 26-04 replaced 22-01: public naming under the old directive was criticised internally as creating a target list for adversaries, so the new directive tracks compliance privately instead.

What could happen next?
  • Meaning

    CISA's move away from public non-compliance naming under BOD 26-04 removes an accountability mechanism BOD 22-01 relied on, with no public data yet available on whether private tracking achieves comparable patch speed.

  • Risk

    Without public naming, oversight bodies such as Congress or the Government Accountability Office lose an early public signal for which federal agencies are falling behind on the worst vulnerabilities.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

CISA· 4 Jul 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.