CISA tore up its KEV patching rulebook on 10 June 2026, replacing the fixed 14-day default with a four-tier risk model that assigns 3-day, 14-day, 60-day, or next-cycle windows depending on how dangerous a flaw actually is.
The change lands without a published scoring rubric, leaving agencies uncertain whether deadlines already in progress, including Arista's 23 June window, still apply. The catalogue has now reached 1,627 entries, and a smaller CISA needed a triage system.
