CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
Summary
Hide ▲
Show ▼
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status, Exploit Automation, and Post-Exploitation Technical Impact. The directive updates BOD 19-02 and BOD 22-01 so agencies focus patching on the highest-risk vulnerabilities and verify whether systems were already compromised before patching. It is a federal cybersecurity mandate meant to reduce risk and improve remediation efficiency across the civilian government enterprise.
Related Happenings
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA zero-trust SASE guidance for TIC 3.0
Public Sector Action
H score30
First: 25.06.2026 14:30
Last: 25.06.2026 14:30
Sources 1
About this happening:
CISA published new guidance on June 24 for federal civilian executive branch agencies to replace legacy internet gateways with SASE as part of the move from TIC...
CISA zero-trust SASE guidance for TIC 3.0
Public Sector ActionAbout this happening: CISA published new guidance on June 24 for federal civilian executive branch agencies to replace legacy internet gateways with SASE as part of the move from TIC...
CISA BOD 26-04 three-day remediation directive
Public Sector Action
H score36
First: 24.06.2026 17:35
Last: 24.06.2026 17:35
Sources 1
About this happening:
CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA BOD 26-04 three-day remediation directive
Public Sector ActionAbout this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA FortiBleed mitigation guidance
Advisory/Mitigation
H score67
First: 19.06.2026 09:47
Last: 19.06.2026 09:47
Sources 1
About this happening:
CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
CISA FortiBleed mitigation guidance
Advisory/MitigationAbout this happening: CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...
Timeline
-
10.06.2026 15:00 3 articles · 1mo ago
CISA issues Binding Operational Directive 26-04 for federal civilian agencies
Legal Policy Action UpdateCISA issued Binding Operational Directive 26-04, requiring federal civilian agencies to assess and align vulnerability management policies around Asset Exposure, Known Exploited Vulnerabilities (KEV) Status, Exploit Automation, and Post-Exploitation Technical Impact. The directive consolidates and updates BOD 19-02 and BOD 22-01, focuses remediation on the highest-risk vulnerabilities, adds expectations to check whether a vulnerable system was already compromised before patching, and reflects the risk of AI-assisted exploitation.
Show sources
- CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities — www.cisa.gov — 10.06.2026 15:00
- CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities — www.cisa.gov — 10.06.2026 15:00
- CISA Orders Agencies to Patch by Risk, Not Severity — www.infosecurity-magazine.com — 11.06.2026 18:00