Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUN

CISA tears up the KEV deadline rulebook

3 min read
09:20UTC

CISA revoked the directive behind its patch-deadline regime on 10 June and replaced it with a risk-tiered model, four days before Arista's deadline under the old order fell. The same fortnight produced Splunk's first-ever KEV entry, a triple CVSS-10 Ubiquiti chain, an 86,644-credential Fortinet leak, and a Five Eyes warning that AI will compress the exploit window to months.

TechnologyASDSOC
Key takeaway

Defenders are losing visibility faster than access, and the new patch regime has not solved that.

This briefing mapped
Regulatory
Infrastructure
Diplomatic

CISA revoked BOD 22-01 on 10 June and replaced it with a risk-tiered model, four days before Arista's deadline under the old order fell due.

Sources profile:This story draws on neutral-leaning sources

CISA tore up its KEV patching rulebook on 10 June 2026, replacing the fixed 14-day default with a four-tier risk model that assigns 3-day, 14-day, 60-day, or next-cycle windows depending on how dangerous a flaw actually is.

The change lands without a published scoring rubric, leaving agencies uncertain whether deadlines already in progress, including Arista's 23 June window, still apply. The catalogue has now reached 1,627 entries, and a smaller CISA needed a triage system. 

NCSC and CISA issued alerts on 18 June after a privately-held database of 86,644 FortiGate credentials across 194 countries surfaced. No zero-day was used.

Sources profile:This story draws on neutral-leaning sources

A database of 86,644 Fortinet firewall login credentials covering 194 countries was found in private hands on 13 June 2026. Each record includes the organisation's sector, revenue band, and employee count: the kind of targeting profile used to plan selective operations, not mass attacks.

NCOSC and CISA issued a joint alert on 18 June recommending factory resets. Attribution points to a Russian-speaking actor, and the dataset's NATO-weighted targeting suggests intelligence preparation rather than opportunistic criminal use. 

Sources:NCSC·SOCRadar

CISA listed CVE-2026-20253 on 18 June, the first Splunk flaw ever added to the KEV catalogue. Splunk confirmed active exploitation the same day.

Sources profile:This story draws on neutral-leaning sources

Splunk Enterprise landed its first-ever entry on CISA's mandatory-patch list on 18 June 2026. CVE-2026-20253 lets an unauthenticated attacker write files into Splunk's configuration folders and execute code when the service restarts, with no login required.

Active exploitation was confirmed just eight days after Splunk shipped the patch. Because Splunk is the detection platform most large SOCs depend on, a compromised instance can blind a security team to every other attack happening across its estate. 

Bishop Fox chained three maximum-severity UniFi OS flaws into a public unauthenticated-root demo. CISA listed all three on 23 June with a 3-day deadline.

Sources profile:This story draws on neutral-leaning sources

Bishop Fox chained three CVSS 10.0 flaws in Ubiquiti's network management software into a public exploit that gives an attacker full control of the device with no login required. CISA added all three to its mandatory-patch list on 23 June with a three-day deadline.

This is the first time the new BOD 26-04 three-day top tier has been used in the wild. Ubiquiti fixed the flaws in UniFi OS Server 5.0.8. The product is deployed across millions of small businesses and managed service provider estates, where a three-day patch window is rarely achievable. 

NCSC chief Richard Horne told RUSI on 17 June that the agency handled more than 200 cyber incidents against UK critical infrastructure in a year, about 75% state-linked.

Sources profile:This story draws on neutral-leaning sources

NCSC chief executive Dr Richard Horne told the RUSI security conference on 17 June 2026 that his agency handled more than 200 cyber incidents against UK critical infrastructure in the past year. About 75 per cent were traced to state actors in Russia, China, or Iran.

Horne also warned that AI tools will allow adversaries to find and exploit infrastructure weaknesses at scale by 2028. The speech landed on the same day the UK's Cyber Security and Resilience Bill moved to the House of Lords, giving peers a concrete incident count to frame their scrutiny. 

Sources:NCSC

The Five Eyes cyber agencies issued their first joint statement on AI cyber risk on 22 June, putting the threat timeline at months, not years.

Sources profile:This story draws on neutral-leaning sources

The Five Eyes intelligence alliance issued its first joint statement on AI and cyberattacks on 22 June 2026, declaring that AI will fundamentally change both attacking and defending. The timeline for AI-enabled mass exploitation of known vulnerabilities is months away, the statement said, not years.

The warning compresses the NCSC chief executive's own 2028 estimate from five days earlier. It lands as the latest context suggesting that current patching deadlines, even the three-day tier in BOD 26-04, may not remain adequate if AI shortens the discovery-to-exploit window. 

Sources:NCSC

A researcher operating as Nightmare Eclipse has published a run of uncoordinated Microsoft zero-day disclosures since March. Microsoft says a fix for the latest is in development.

Sources profile:This story draws on neutral-leaning sources

Nightmare Eclipse published a fifth unpatched Windows Defender flaw around 17 June 2026, following four similar releases since March. The researcher cites a bug-bounty payment dispute with Microsoft; Microsoft says a patch for CVE-2026-50656 is under development with no scheduled date.

This beat's prior Patch Tuesday coverage reported the same RoguePlanet flaw at CVSS 9.6 and confirmed as actively exploited, with no CVE assigned. SecurityWeek's single-source account rates it CVSS 7.8 and reports no confirmed exploitation. CVSS score and exploitation status diverge across the two accounts. No patch has shipped as of 24 June 2026. 

Sources:SecurityWeek
Closing comments

Sideways with pockets of upward pressure. BOD 26-04 could reduce dwell time on the highest-severity flaws if CISA publishes scoring guidance before Q3 2026; without it the 3-day top tier carries no enforcement mechanism because agencies cannot determine which tier a flaw falls into. The countervailing pressure: the FortiBleed dataset of 86,644 credentials has been in private custody since at least 13 June 2026 without appearing on dark-web forums, the same pre-positioning pattern Volt Typhoon used in 2024-2025 before moving to OT disruption. The specific escalation trigger is FortiBleed's custody status: a dark-web listing would close the intelligence-preparation phase and open simultaneous targeted campaigns across 194 countries. CVE-2026-50656 in Windows Defender has no Microsoft patch date as of 24 June 2026.

AI-assisted, human-edited under the editorial responsibility of Bannermedia Ltd. Reviewed by Ed Woodcock on 24 June 2026. Editorial standards.

Different Perspectives
CISA and US federal agencies
CISA and US federal agencies
CISA issued BOD 26-04 to replace a compliance framework that broke publicly three times in six weeks, but the handover left a binding Arista deadline hanging under the revoked directive with no public enforcement signal after it lapsed on 23 June. A proposed $707 million FY27 cut means enforcement capacity is shrinking as the catalogue grows.
NCSC and UK critical infrastructure operators
NCSC and UK critical infrastructure operators
Dr Richard Horne put more than 200 CNI incidents in 12 months on the public record and framed today's unpatched vulnerabilities as a conflict-time risk, not a compliance one; the UK Cyber Security and Resilience Bill is in the Lords but still lacks the ransomware-payment reporting regime that was dropped in Commons.
Five Eyes allied agencies
Five Eyes allied agencies
The joint AI cyber risk statement of 22 June, signed by NCSC, CISA, ASD, CCCS, and NCSC-NZ, asserts that the window between flaw publication and mass exploitation is now measured in months and narrowing; this is the first coordinated allied statement to set an operational timeline rather than a strategic warning.
Enterprise security operations centres (SIEM operators)
Enterprise security operations centres (SIEM operators)
CVE-2026-20253 turns the detection platform itself into an attack surface; a compromised Splunk instance can suppress alerts across an entire estate before any intrusion is logged, meaning patching the detector is now as urgent as patching the perimeter devices it watches.
EU / ENISA and NIS2-regulated organisations
EU / ENISA and NIS2-regulated organisations
BOD 26-04's risk-tiered model is being watched by ENISA as a potential template for updating NIS2 remediation guidance; EU critical-entity operators face both the FortiBleed credential exposure across 194 countries and AI-threat timeline compression without a parallel directive change in this window.