Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

CISA tears up its KEV deadline rules

4 min read
12:09UTC

CISA revoked BOD 22-01 on 10 June and replaced it with a risk-tiered model, four days before Arista's deadline under the old order fell due.

TechnologyDeveloping
Key takeaway

The federal patch-deadline era ended because exploitation outran it, not because anyone won the argument.

The US Cybersecurity and Infrastructure Security Agency (CISA) revoked BOD 22-01 (Binding Operational Directive 22-01) on 10 June and replaced it with the risk-tiered BOD 26-04 1. BOD 22-01 had been the order behind CISA's mandatory patch deadlines for US federal agencies since 2021, built on the agency's catalogue of KEV (Known Exploited Vulnerabilities), its list of flaws confirmed as actively exploited. Under the new directive, agencies no longer get one due date per flaw. They score each one across four dimensions, asset internet exposure, KEV catalogue status, exploit-automation feasibility, and post-exploitation impact, then assign a 3-day, 14-day, 60-day, or next-upgrade-cycle window 2. The KEV catalogue had passed 1,627 entries by 23 June, roughly two new flaws a day to triage under the new rules 3.

The shift answers a problem this beat has tracked for four months: deadlines outrunning the patches meant to meet them. CISA set a PAN-OS deadline that landed four days before the patch shipped ; it listed an Exchange OWA flaw with a federal cut-off and no fix at all ; and on 9 June Arista Networks formally refused to patch a KEV-listed flaw, leaving agencies bound to remediate something the vendor would not repair . BOD 22-01 assumed a patch existed or was imminent, and had no answer for any of those cases.

The transition carries a live irony. Arista's 23 June deadline, now passed, was set under a directive CISA had already revoked on 10 June . Whether it still bound federal Arista customers after the revocation was never resolved in public, and CISA has named no enforcement action since it lapsed.

Treat the reframe with care. BOD 26-04 maps closely onto what CISA already did case by case, since Check Point drew a 3-day window and Arista 14 under the old order 4. The new directive still carries no explicit clause for a vendor that declines to patch outright, so the Arista problem is reclassified into the risk tiers rather than closed. Revoking the foundational directive is materially significant; the claim that it ends the patch-gap era is not.

Deep Analysis

In plain English

CISA is the US government agency responsible for telling federal departments and agencies which software vulnerabilities they must fix, and how fast. Until 10 June 2026, the rule was simple: once a flaw went on its official list (called the Known Exploited Vulnerabilities catalogue), agencies had a fixed window, usually 14 days, to patch. The new rule, BOD 26-04, asks: how dangerous is this specific flaw, in this specific situation? A flaw that is being actively attacked on the internet, can be exploited automatically, and gives the attacker full control of a system gets three days. A less severe flaw with no evidence of active exploitation might get 60 days or simply the next planned upgrade. The idea is to focus urgent effort where risk is highest, rather than treating every flaw identically.

Deep Analysis
Root Causes

BOD 22-01 collapsed under three converging pressures. First, the fixed-deadline model assumed vendors would patch before federal deadlines, a premise that broke publicly when the PAN-OS CVE-2026-0300 deadline preceded the patch by four days , and again when CISA listed Exchange CVE-2026-42897 with no remediation path .

Second, Arista's confirmed refusal to patch CVE-2026-7473 exposed the absence of any enforcement mechanism against non-cooperative vendors: the directive bound federal agencies, not the vendors supplying them.

Third, the KEV catalogue grew 42 entries since late April to reach 1,627, generating a volume of deadlines that CISA could not monitor for compliance after the Trump FY27 budget proposed cutting the agency by $707 million and 860 positions. A smaller agency faced with more deadlines produces selective enforcement; risk-tiering is partly a staffing adaptation.

What could happen next?
  • Risk

    In-flight BOD 22-01 deadlines, including Arista's 23 June window, entered a period of transitional ambiguity on 10 June; federal agencies that were tracking these deadlines now lack a clear compliance posture until CISA publishes BOD 26-04 classification guidance.

    Immediate · Assessed
  • Consequence

    Cyber insurers and procurement auditors using KEV status as a mandatory-patch proxy must rebuild their assessment templates; the existing 14-day default is no longer universal.

    Short term · Reported
  • Precedent

    BOD 26-04 is the first US federal directive to formally codify risk-tiered vulnerability remediation; if it reduces patch cycle time for the highest-severity flaws, it will become the model for allied-nation NIS2 and NCSC guidance updates.

    Medium term · Suggested
First Reported In

Update #8 · CISA tears up the KEV deadline rulebook

CISA· 24 Jun 2026
Read original
Causes and effects
This Event
CISA tears up its KEV deadline rules
The benchmark every federal and enterprise patch programme calibrates against has changed from a single deadline per flaw to a four-dimension risk score.
Led to
Triple CVSS-10 Ubiquiti chain hits root
BOD 26-04's 3-day top tier is first operationalised by the Ubiquiti KEV batch on 23 June, making this the new regime's debut in the wild.
Occurred 23 Jun 2026
Read story →
SharePoint patch clock runs out today
BOD 26-04's risk-tiered framework set the remediation window applied to the SharePoint deserialisation flaw.
Occurred 1 Jul 2026
Read story →
BOD 26-04, a fortnight of triage
BOD 26-04 is the risk-tiered directive whose first fortnight this event quantifies.
Occurred 4 Jul 2026
Read story →
A quiet KEV fortnight, then a 2008 bug
BOD 26-04's risk-tiered directive from June may be reshaping the pace and selection of this fortnight's KEV additions.
Occurred 14 Jul 2026
Read story →
CISA's KEV list runs a month late
CISA's risk-tiered BOD 26-04, issued 10 June, is the directive whose patching clock the FortiSandbox KEV entry starts.
Occurred 16 Jul 2026
Read story →
KEV patch clocks fell to three days
BOD 26-04's 10 June issuance is the directive whose deadline allocation this recount measures.
Occurred 28 Jul 2026
Read story →
Arista, Fortinet and Cisco flaws listed
The three new KEV entries are catalogued under BOD 26-04's risk-tiered deadline allocation.
Occurred 28 Jul 2026
Read story →
Phase II asks agencies for paperwork
Phase II is the 60-day checkpoint set by the June directive.
Occurred 9 Jun 2026
Read story →
KEV three-day deadline share fell to 65%
BOD 26-04's risk-tiered per-entry windows, replacing BOD 22-01, produced the falling three-day share observed in August's KEV additions.
Occurred 2 Sept 2026
Read story →
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.