CISA Tells Federal Agencies To Patch Smarter With New BOD 26-04

CISA's new Binding Operational Directive 26-04 replaces CVSS-only patching across U.S. civilian agencies with a risk-based framework anchored on exploitation, exposure and impact.

CISA Tells Federal Agencies To Patch Smarter With New BOD 26-04

The U.S. Cybersecurity and Infrastructure Security Agency has issued Binding Operational Directive 26-04, ordering federal civilian agencies to rebuild their vulnerability programs around real-world risk rather than raw CVSS scores.

What the directive does

Released June 10 and detailed by CISA on June 11, BOD 26-04 introduces a framework that lets agencies prioritize remediation across four signals: whether the vulnerability is on an internet-facing system, whether it sits in CISA's Known Exploited Vulnerabilities (KEV) catalog, whether it can be exploited at scale through automation, and whether successful exploitation gives an attacker partial or total control. The most urgent flaws — KEV-listed, internet-facing, automatable and full-control — must be remediated within three days and trigger a mandatory forensic triage.

Why CVSS alone is not enough

BOD 26-04 supersedes both BOD 19-02 (2019) and BOD 22-01 (2021), and it formally retires CVSS as the sole prioritization metric for civilian agencies. CISA said the patching problem has become 'nearly unmanageable' as AI tools accelerate both vulnerability research and exploit development. Agencies have 60 days to update remediation playbooks and 180 days to be fully compliant with the new clocks.

CISA risk-based patching guidance

What's not in scope

The directive concentrates on the network perimeter. CISA was up-front that core-network vulnerabilities are not held to the same urgency — not because they don't matter, but because adversaries usually breach the core through living-off-the-land techniques that demand hardening and phishing-resistant MFA rather than patching.

Lands amid a brutal vulnerability week

The order arrives in the middle of one of 2026's worst patch windows. Microsoft just shipped a record June Patch Tuesday with 200 fixes and three zero-days, while a RoguePlanet zero-day bypassed Microsoft Defender within hours and Cisco's SD-WAN Manager came under active attack. CISA says it will refresh BOD 26-04 implementation guidance on a rolling basis as the threat picture shifts.

Reporting based on coverage from CISA, Help Net Security and CyberScoop.

Category: Cyber Security

Tags: Security Cybersecurity Robotics Regulation AI Regulation Robotics Policy AI Act

Related Articles