Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»CISA Closes Ten Emergency Directives After Federal Cyber Reviews
News

CISA Closes Ten Emergency Directives After Federal Cyber Reviews

Team-CWDBy Team-CWDJanuary 12, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Ten Emergency Directives issued between 2019 and 2024 have been formally retired by the US Cybersecurity and Infrastructure Security Agency (CISA) following a review that found their objectives had been met.

The decision marks the most significant number of Emergency Directives closed at once and reflects changes in how cyber-risk is managed across federal civilian agencies.

The update follows CISA’s assessment that required remediation actions have either been fully implemented by Federal Civilian Executive Branch agencies or incorporated into Binding Operational Directive 22-01.

That standing directive addresses the ongoing risk posed by known exploited vulnerabilities (KEVs) and now serves as the primary mechanism for managing those issues.

From Temporary Mandates to Ongoing Controls

Emergency Directives are issued to address urgent and imminent threats and are intended to remain active only as long as necessary. CISA said sustained coordination with federal agencies helped resolve the underlying risks, embed cybersecurity best practices and reduce reliance on time-limited emergency measures.

“As the operational lead for federal cybersecurity, CISA leverages its authorities to strengthen federal systems and defend against unacceptable risks,” said acting director, Madhu Gottumukkala.

“The closure of these ten Emergency Directives reflects CISA’s commitment to operational collaboration across the federal enterprise.”

Several of the retired directives were linked to specific Common Vulnerabilities and Exposures (CVEs). Those issues are now tracked through CISA’s KEV catalog, which standardizes how agencies identify and remediate widely exploited flaws. 

Read more on federal cybersecurity: US Federal Judiciary Tightens Security Following Escalated Cyber-Attacks

Emergency Directives Now Closed

The directives no longer in force include:

  • ED 19-01 addressing DNS infrastructure tampering

  • ED 20-02 through ED 20-04 related to Windows and Netlogon vulnerabilities

  • ED 21-01 through ED 21-04 covering SolarWinds Orion, Microsoft Exchange, Pulse Connect Secure and Windows Print Spooler

  • ED 22-03 focused on VMware vulnerabilities

  • ED 24-02 concerning the nation-state compromise of Microsoft corporate email systems

CISA said three of these directives (19-01, 21-01 and 24-02) were closed after determining their requirements no longer aligned with the current risk posture or operational practices.

Emergency Directives will continue to be issued when needed, but CISA emphasized long-term risk reduction increasingly relies on standardized directives and secure-by-design principles across federal systems.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCoolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances
Next Article Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Children and chatbots: What parents should know

January 23, 2026

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.