Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

KEV patch clocks fell to three days

4 min read
12:09UTC

CISA gave federal agencies three days to patch a hard-coded password in Cisco's firewall console on 29 July. Recounting the catalogue shows 34 of the 39 entries added since 10 June carry a window that short.

TechnologyAssessed
Key takeaway

Recount the KEV due-date spread monthly; the published range no longer describes federal practice.

CISA gave federal agencies three days to patch Cisco Secure Firewall Management Center on 29 July, after adding a hard-coded password flaw in the console to its Known Exploited Vulnerabilities catalogue 1. CISA, the US Cybersecurity and Infrastructure Security Agency, maintains that catalogue as the list of flaws it has confirmed under active attack. The dates attached to each entry bind federal civilian agencies, and vulnerability-management Teams across the private sector inherit them through the scanning products that read the feed, without being bound by the directive at all.

That three-day window is no longer the exception. Of the 39 entries added between 10 June and 29 July, 34 carry a remediation deadline of three days or less, 87 per cent; of the 31 entries added between 1 May and 10 June, 12 did, 39 per cent 2. Every entry carrying both a dateAdded and a dueDate was counted, the gap measured in days, and the same arithmetic applied on both sides of 10 June, with entries lacking a dueDate excluded throughout. The median window fell from 14 days to three and the mean from 9.45 days to 4.41. The published range did not move, since both directives allow the same 3-to-14 spread, but the fortnight end of it has emptied: 58 per cent of the earlier entries allowed a fortnight or more, against 13 per cent of the later ones.

BOD 26-04 took effect on 10 June , replacing the fixed clocks of its predecessor with risk-tiered triage that assigns a window per entry rather than per class, and a security chief who read "risk-based" as room to breathe has been reading it backwards. Additions did not slow to match: entries reached the catalogue at roughly 0.78 per day on either side of the changeover, so what moved is the clock attached to a flaw, not the number of flaws attracting one 3. Bishop Fox's chained Ubiquiti UniFi OS Server flaws drew the same short window on 23 June , which read as an outlier at the time.

Seven weeks of register data cannot settle two confounds. If the newer entries skew towards edge appliances and management consoles, that class drew short clocks under the old regime as well, and composition alone could produce the whole drop; the catalogue has also gone quiet since 29 July, which reads equally as a summer lull in confirmed exploitation or as triage holding listings back. Both readings sat open when this beat first raised the doctrine-versus-composition question on 4 July , and only a monthly recount will close them.

Deep Analysis

In plain English

CISA is the US government's cyber-defence agency. It keeps a public list, the Known Exploited Vulnerabilities catalogue, of software flaws that hackers are already using in real attacks, and it tells federal agencies how fast they must fix each one. Until June, every flaw on the list got roughly the same countdown: about two weeks. Since then, CISA has switched to a system that scores how dangerous each flaw looks and hands out a much shorter deadline, sometimes as little as three days, to the ones it rates worst. The numbers now show that shorter deadline has become the norm rather than the exception: most new entries in the past seven weeks got the fastest possible clock.

Deep Analysis
Root Causes

CISA's risk-tiering formula scores four inputs: asset internet exposure, KEV status, exploit-automation feasibility and post-exploitation impact. Only the top tier draws sub-week deadlines; the rest fall into 14-day, 60-day or next-upgrade-cycle bands.

The compression is structurally possible only because BOD 26-04 replaced a single deadline field with four, giving CISA discretion to slot more flaws into the top band without amending the directive itself. Under BOD 22-01, moving a flaw's deadline meant a new directive or a public exception; under BOD 26-04, it is a scoring decision made inside the agency, invisible until the catalogue entry appears.

What could happen next?
  • Consequence

    Enterprise patch programmes that adopt CISA's tiering as a benchmark will face compressed prioritisation windows even outside the federal mandate.

  • Risk

    If the compression reflects catalogue composition rather than genuine escalation, organisations may over-index on speed for a shrinking pool of high-severity entries while missing the ones now parked in 60-day or next-upgrade-cycle tiers.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.