CISA moves to risk-based CVE triage

- CISA’s June 10, 2026 directive BOD 26-04 told federal civilian agencies to rank vulnerabilities by risk instead of patching mainly by CVSS or KEV status. - CISA said only the highest-risk vulnerabilities — combining public exposure, automation, full-control impact and known exploitation — must be remediated within three days. - NIST said on July 8 it released SP 1326, a supply-chain due-diligence quick-start guide for acquirers.

CISA changed how U.S. civilian agencies are supposed to decide what gets patched first. On June 10, the agency issued Binding Operational Directive 26-04, which replaces a mostly list-driven model with a risk-based triage framework for vulnerability remediation across the Federal Civilian Executive Branch. The directive tells agencies to weigh four factors — public exposure, evidence of exploitation in the wild, whether exploitation can be automated, and whether exploitation would give an attacker full control of a system — and then assign remediation urgency from that combination. ### What did CISA actually change? BOD 26-04 is a compulsory directive for federal civilian executive branch agencies, and CISA said it is meant to focus patching on the “areas of highest risk” rather than treating all vulnerabilities and systems equally. The directive builds on the Known Exploited Vulnerabilities catalog created under BOD 22-01, but it no longer treats KEV status alone as the organizing principle for federal remediation. (cisa.gov) Chris Butera, CISA’s acting executive assistant director for cybersecurity, and Jonathan Spring, a senior technical advisor, wrote in a June 10 CISA post that the framework lets agencies defer lower-priority vulnerabilities and concentrate on the highest-risk cases. They said AI is increasing the pace at which flaws are found and narrowing defenders’ response windows. ### Which vulnerabilities move to the front of the line? (cisa.gov) CISA said the greatest risk comes from vulnerabilities with four traits: they are publicly exposed, can be fully automated by an attacker, would give an attacker full control of a system, and show evidence of real-world exploitation through KEV status. Under that model, only the top-risk set has to be patched within three days, while lower-risk issues get longer timelines and may be deferred to a later upgrade cycle. (cisa.gov) The implementation guidance says agencies must identify quickly whether a KEV addition meets the threshold for remediation in fewer than three days and, if so, begin forensic triage to determine whether systems have already been affected. CISA said the guidance includes scoping, evidence preservation, containment and escalation steps for those urgent cases. (cisa.gov) ### Why is CISA moving away from broad patch-everything urgency? CISA cited patching performance data in explaining the shift. In the June 10 blog post, the agency said Verizon’s 2026 Data Breach Investigations Report found only 26% of vulnerabilities on CISA’s KEV catalog were fully remediated by organizations in 2025, down from 38% a year earlier, while the median time to full resolution rose to 43 days. (cisa.gov) That same post said an initial analysis at one large civilian agency found only 1% of vulnerability instances fell into the three-day category, while more than 60% could be deferred until the next system upgrade. CISA presented that as evidence that tighter triage could compress the most urgent deadlines without forcing the same pace across the entire backlog. ### How does this connect to NIST and the NVD backlog? (cisa.gov) NIST said on April 15 that it was changing NVD operations to address record CVE growth with a new risk-based model. The agency said the change was intended to help it manage current volume while modernizing the National Vulnerability Database for long-term sustainability, and it added stakeholder-specific vulnerability categorization data sourced from CISA’s authorized data publisher. (cisa.gov) NVD records still show gaps in enrichment for some recent entries. Several 2026 records on the NVD site say NIST assessments are “not yet provided,” while the database notes that enrichment efforts reference public information and that updates will be added when available. ### What else changed this week around federal cyber guidance? NIST said on July 8 that it released the finalized Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide, SP 1326. (nist.gov) The guide is aimed at helping acquirers research suppliers and products before procurement decisions, and it identifies five due-diligence components: foreign ownership, control or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers. (nvd.nist.gov) FedRAMP said on June 16 that cloud service providers will have to adopt updated vulnerability detection, response, evaluation and reporting rules by Dec. 7, 2026 to align with CISA’s directive. FedRAMP said providers following those rules will meet the timelines and prioritization approach set out in BOD 26-04. ### What happens next for agencies and vendors? Dec. 7, 2026 is the FedRAMP adoption date for aligned cloud-provider rules, and CISA said it will continue updating its BOD 26-04 implementation guidance page with new material. (nist.gov) Agencies, vendors and cloud providers will also keep using the KEV catalog, which CISA describes as the authoritative list of vulnerabilities known to be exploited in the wild. (fedramp.gov)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.