Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

KEV three-day deadline share fell to 65%

2 min read
12:09UTC

CISA added 37 entries to its Known Exploited Vulnerabilities catalogue between 3 August and 2 September, and 24 of them carried a three-day remediation deadline. The previous stretch ran at 87 per cent.

TechnologyAssessed
Key takeaway

Under a risk-tiered directive, CISA's three-day patch deadline is no longer close to universal.

CISA, the US Cybersecurity and Infrastructure Security Agency, added 37 entries to its Known Exploited Vulnerabilities catalogue between 3 August and 2 September, and 24 of them, 65 per cent, carry a remediation deadline of three days 1. The catalogue lists flaws CISA has confirmed are already being used in attacks, and each entry carries a date by which federal civilian agencies must fix it. Across the previous stretch, 10 June to 29 July, 34 of 39 entries carried that window, 87 per cent . The median held at three days on both sides; the concentration around it loosened.

Those counts come from the cisagov/KEV-data repository on GitHub, a CISA-maintained mirror carrying catalogue version 2026.09.02, because the catalogue's own page and its JSON feed both refused our requests. It is CISA's data one hop from the source, and nothing here was read off the official catalogue page.

Binding Operational Directive BOD 22-01 was revoked on 10 June and replaced by BOD 26-04, which assigns a window per entry rather than per class . A directive built to tier by risk produces a wider spread of deadlines by design, so a mix that has stopped clustering at three days reads as the instrument working rather than failing. The Zimbra command-injection flaw reached the catalogue on 21 August, four days after Poland's national CERT published on it.

The effect lands hardest on everyone the directive does not bind. Vulnerability Teams outside the federal estate inherit these dates through the scanning products that read the feed, without being bound by the directive at all, and a patch cadence built when nearly nine entries in ten said three days now takes its urgency from a catalogue where a third say something slower. Two periods do not make a trend, and the mix of products being exploited could move the share on its own.

Deep Analysis

In plain English

CISA, the US government's main cyber agency, keeps a list of vulnerabilities it knows are being actively exploited, called the Known Exploited Vulnerabilities catalogue. When a flaw is added, US federal agencies must fix it within a set number of days, often three. CISA added 37 new entries between 3 August and 2 September. A smaller share of them, 65 per cent versus 87 per cent in the previous stretch, carried the tightest three-day deadline.

Deep Analysis
Root Causes

CISA's three-day remediation deadline applies to federal civilian agencies under Binding Operational Directive 22-01, so a shift in what share of new KEV entries get that tightest clock reflects CISA's own risk grading of each entry, not a change in the underlying vulnerabilities' severity.

The drop from 87 per cent to 65 per cent carrying the three-day deadline, while the median held at three days on both sides, means CISA added a wider spread of urgency levels this stretch rather than uniformly treating every new entry as maximally urgent.

First Reported In

Update #13 · Four privileged platforms under live attack

CISA (cisagov/kev-data GitHub repository)· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.