Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Over 80% of Sports Organizations Targeted by Hackers in the Last Year

June 12, 2026

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

June 12, 2026

GitHub to Update npm to Thwart Software Supply Chain Attacks

June 12, 2026
Facebook X (Twitter) Instagram
Friday, June 12
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»CISA Orders Agencies to Patch by Risk, Not Severity
News

CISA Orders Agencies to Patch by Risk, Not Severity

Team-CWDBy Team-CWDJune 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


US federal agencies have been instructed to overhaul their vulnerability management practices, shifting away from rigid, deadline-driven patching toward a risk-based approach that prioritizes the most actively exploited threats, under new guidance from the Cybersecurity and Infrastructure Security Agency (CISA).

Binding Operational Directive 26-04, issued on June 10, ties each deadline to risk: three days, plus a forensic check for signs of intrusion, for the most dangerous flaws, with longer windows for less severe combinations and deferral for genuinely low-risk bugs, in some cases until a system’s next major upgrade. It consolidates two previous mandates, BOD 19-02 and the KEV-focused BOD 22-01.

CISA cast it as a response to a threat picture in which AI helps attackers find and weaponize bugs faster, shrinking defenders’ window once a patch ships, as the volume of disclosed flaws outpaces blanket patching.

The directive also pairs its tightest deadlines with a forensic step. When an agency patches the most serious flaws, it must check whether attackers have already exploited them, since a fix rarely evicts an intruder.

Read more on CISA directives: CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws

Risk Replaces the Severity Score

For years, CVSS severity scores drove prioritization, BOD 26-04 drops that. Revoking the old directive means agencies are no longer required to use CVSS to prioritize, since, as CISA noted, a severity label alone doesn’t dictate what to fix first.

The directive instead weighs four factors:

  • Asset exposure: whether the system is publicly reachable

  • KEV status: whether the flaw is on CISA’s Known Exploited Vulnerabilities (KEV) catalog

  • Exploit automation: whether an adversary can automate every step needed to exploit it

  • Technical impact: whether a successful attack grants partial or total control

Acting CISA director, Nick Andersen, said the directive lets agencies “focus their efforts on the areas of highest risk” and defer the rest. He urged private-sector and infrastructure operators to follow suit.

Doubts About the Execution

Agencies have 180 days, until around December 7, before they must meet the directive’s remediation timelines in every case. Practitioners broadly welcomed the aim while warning that the hard part is execution.

Knowing a bug is exploited, which the KEV catalog already flags, is only half the job, said Sunil Gottumukkala, CEO of agentic remediation platform provider Averlon. He said, “The other half is whether it matters in your environment.”

Denis Calderone, CTO of AI security firm Suzu Labs, agreed, “CVSS alone has never been a reliable way to decide which vulnerabilities to prioritize.” However, he questioned who will ensure agencies run real risk assessments rather than tick a compliance box, particularly given what he called deep cuts to CISA’s budget and workforce.

Calderone urged defenders to build their own stack now including KEV status, Exploit Prediction Scoring System (EPSS) probabilities and local context.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleClaude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
Next Article Fake Sites, Banking Malware, and Stolen Logins
Team-CWD
  • Website

Related Posts

News

Over 80% of Sports Organizations Targeted by Hackers in the Last Year

June 12, 2026
News

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

June 12, 2026
News

GitHub to Update npm to Thwart Software Supply Chain Attacks

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Is it OK to let your children post selfies online?

February 17, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.