CISA BOD 26-04 remediation requirements
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new KEV-based reporting duties.
Related Happenings
CISA BOD 26-04 three-day remediation directive
Public Sector Action
H score36
First: 24.06.2026 17:35
Last: 24.06.2026 17:35
Sources 1
About this happening:
CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA BOD 26-04 three-day remediation directive
Public Sector ActionAbout this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA orders FCEB Ivanti Sentry remediation under BOD 26-04
Public Sector Action
H score36
First: 12.06.2026 11:26
Last: 12.06.2026 11:26
Sources 1
About this happening:
CISA ordered FCEB agencies to secure Ivanti Sentry within three days after confirming CVE-2026-10520 is being actively exploited, creating immediate remedi...
CISA orders FCEB Ivanti Sentry remediation under BOD 26-04
Public Sector ActionAbout this happening: CISA ordered FCEB agencies to secure Ivanti Sentry within three days after confirming CVE-2026-10520 is being actively exploited, creating immediate remedi...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
How related:
Binding Operational Directive 26-04, issued on June 10, ties each deadline to risk: three days, plus a forensic check for signs of intrusion, for the most dangerous flaws, with longer windows for less severe combinations and deferral for genuinely low-risk bugs, in some cases until a system's next major upgrade.
About this happening:
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionHow related: Binding Operational Directive 26-04, issued on June 10, ties each deadline to risk: three days, plus a forensic check for signs of intrusion, for the most dangerous flaws, with longer windows for less severe combinations and deferral for genuinely low-risk bugs, in some cases until a system's next major upgrade.
About this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA launches KEV Nomination Form
Public Sector Action
H score38
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
H score37
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
Timeline
-
11.06.2026 15:46 2 articles · 1mo ago
CISA issues Binding Operational Directive 26-04 for FCEB agencies
Initial DisclosureCISA issued Binding Operational Directive 26-04 for Federal Civilian Executive Branch (FCEB) agencies, superseding BOD 19-02 and BOD 22-01 and prioritizing security updates for publicly exposed or KEV-listed vulnerabilities with remediation deadlines as short as three days.
Show sources
- CISA tells govt agencies to patch critical exploited flaws in 3 days — www.bleepingcomputer.com — 11.06.2026 15:46
- CISA Orders Agencies to Patch by Risk, Not Severity — www.infosecurity-magazine.com — 11.06.2026 18:00
-
11.06.2026 15:46 2 articles · 1mo ago
Federal agencies must update vulnerability management policies within 60 days
Mitigation Patch UpdateFCEB agencies must update vulnerability management policies, refresh asset inventories, and automate KEV status reporting so remediation decisions use CVE and KEV data.
Show sources
- CISA tells govt agencies to patch critical exploited flaws in 3 days — www.bleepingcomputer.com — 11.06.2026 15:46
- CISA tells govt agencies to patch critical exploited flaws in 3 days — www.bleepingcomputer.com — 11.06.2026 15:46
-
11.06.2026 15:46 1 articles · 1mo ago
Federal agencies must follow the new remediation timelines and report detailed asset metadata
Mitigation Patch UpdateBy the 180-day implementation point, FCEB agencies must follow the new remediation timelines and continuously monitor and report detailed asset metadata across on-premise, third-party hosted, and FedRAMP/non-FedRAMP cloud environments.
Show sources
- CISA tells govt agencies to patch critical exploited flaws in 3 days — www.bleepingcomputer.com — 11.06.2026 15:46