CISA, the US Cybersecurity and Infrastructure Security Agency, added 37 entries to its Known Exploited Vulnerabilities catalogue between 3 August and 2 September, and 24 of them, 65 per cent, carry a remediation deadline of three days 1. The catalogue lists flaws CISA has confirmed are already being used in attacks, and each entry carries a date by which federal civilian agencies must fix it. Across the previous stretch, 10 June to 29 July, 34 of 39 entries carried that window, 87 per cent . The median held at three days on both sides; the concentration around it loosened.
Those counts come from the cisagov/KEV-data repository on GitHub, a CISA-maintained mirror carrying catalogue version 2026.09.02, because the catalogue's own page and its JSON feed both refused our requests. It is CISA's data one hop from the source, and nothing here was read off the official catalogue page.
Binding Operational Directive BOD 22-01 was revoked on 10 June and replaced by BOD 26-04, which assigns a window per entry rather than per class . A directive built to tier by risk produces a wider spread of deadlines by design, so a mix that has stopped clustering at three days reads as the instrument working rather than failing. The Zimbra command-injection flaw reached the catalogue on 21 August, four days after Poland's national CERT published on it.
The effect lands hardest on everyone the directive does not bind. Vulnerability Teams outside the federal estate inherit these dates through the scanning products that read the feed, without being bound by the directive at all, and a patch cadence built when nearly nine entries in ten said three days now takes its urgency from a catalogue where a third say something slower. Two periods do not make a trend, and the mix of products being exploited could move the share on its own.
