CISA orders FCEB GitLab patching under BOD 22-01
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered FCEB agencies to patch GitLab CE/EE against CVE-2021-39935, forcing remediation of an actively exploited SSRF flaw within three weeks. The deadline is February 24, 2026 under BOD 22-01. CISA said the flaw poses a significant risk to the federal enterprise and urged broader organizations to prioritize mitigations.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score46
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
Pentagon suspends CMMC phase two for 60-day review
Public Sector Action
H score24
First: 14.07.2026 09:37
Last: 14.07.2026 09:37
Sources 1
About this happening:
The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
Pentagon suspends CMMC phase two for 60-day review
Public Sector ActionAbout this happening: The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
Timeline
-
04.02.2026 17:42 2 articles · 5mo ago
CISA orders FCEB patching for GitLab CVE-2021-39935
Legal Policy Action UpdateCISA added CVE-2021-39935, a GitLab server-side request forgery flaw, to its exploited-in-the-wild list and ordered Federal Civilian Executive Branch agencies to patch affected systems within three weeks, by February 24, 2026, under Binding Operational Directive (BOD) 22-01. CISA also urged other organizations to prioritize mitigations against ongoing attacks, while GitLab had already patched the flaw in December 2021.
Show sources
- CISA warns of five-year-old GitLab flaw exploited in attacks — www.bleepingcomputer.com — 04.02.2026 17:42
- CISA warns of five-year-old GitLab flaw exploited in attacks — www.bleepingcomputer.com — 04.02.2026 17:42