Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA orders FCEB GitLab patching under BOD 22-01

Public Sector Action
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

CISA ordered FCEB agencies to patch GitLab CE/EE against CVE-2021-39935, forcing remediation of an actively exploited SSRF flaw within three weeks. The deadline is February 24, 2026 under BOD 22-01. CISA said the flaw poses a significant risk to the federal enterprise and urged broader organizations to prioritize mitigations.

Related Happenings

CISA orders FCEB patching for CVE-2026-9082

Public Sector Action
First: 26.05.2026 11:46 Last: 26.05.2026 11:46 Sources 1

About this happening: **CISA** added **CVE-2026-9082** to the **KEV Catalog** and ordered **FCEB agencies** to patch **Drupal** by **May 27**, turning an actively exploited flaw into a mandatory federa...

Congress demands CISA answers on GitHub credential leak

Public Sector Action
First: 22.05.2026 19:34 Last: 22.05.2026 19:34 Sources 1

About this happening: **Lawmakers in both houses of Congress** demanded answers from **CISA** after a contractor exposed **AWS GovCloud keys** and other secrets on **public GitHub**. The letters presse...

CISA emergency patch deadline for Ivanti EPMM

Public Sector Action
First: 08.05.2026 15:16 Last: 08.05.2026 15:16 Sources 1

About this happening: CISA ordered **U.S. federal agencies** to patch **Ivanti EPMM** by **midnight Sunday, May 10** after adding **CVE-2026-6973** to its list of vulnerabilities exploited in attacks....

CISA KEV order for Copy Fail on federal Linux devices

Public Sector Action
First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: **CISA** added **Copy Fail** to the **Known Exploited Vulnerabilities (KEV) Catalog**, making the Linux flaw a federal remediation priority. The agency ordered **federal agencies*...

CISA KEV action for CVE-2026-31431 and FCEB remediation

Public Sector Action
First: 03.05.2026 09:26 Last: 03.05.2026 09:26 Sources 1

About this happening: CISA added **CVE-2026-31431** to its **KEV catalog**, putting **Federal Civilian Executive Branch (FCEB)** agencies on notice to remediate an actively exploited Linux privilege-es...

Timeline

  1. 04.02.2026 17:42 2 articles · 3mo ago

    CISA orders FCEB patching for GitLab CVE-2021-39935

    Legal Policy Action Update

    CISA added CVE-2021-39935, a GitLab server-side request forgery flaw, to its exploited-in-the-wild list and ordered Federal Civilian Executive Branch agencies to patch affected systems within three weeks, by February 24, 2026, under Binding Operational Directive (BOD) 22-01. CISA also urged other organizations to prioritize mitigations against ongoing attacks, while GitLab had already patched the flaw in December 2021.

    Show sources