Security & Threat Intelligence · 25.07.2026, 15:29 UTC
CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | Tenable Research ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch. Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
CISA issued BOD 26-04, which replaces BOD 22-01 with a four-variable vulnerability prioritization model requiring federal agencies to patch the most dangerous vulnerabilities in as few as three days.Key takeawaysBOD 26-04 replaces BOD 22-01 with a four-variable risk model that assigns graduated remediation timelines, from as few as three days with mandatory forensic triage for the most dangerous vulnerabilities to full deferral for the lowest-risk ones, ending the era of flat, one-size-fits-all patching deadlines for federal agencies. The transition represents a significant operational lift at a time when AI is compressing the window between vulnerability disclosure and weaponization, and industry remediation rates are declining: only 26% of KEV vulnerabilities were fully remediated in 2025 according to the 2026 Verizon DBIR, down from 38% the prior year. Organizations that have invested in continuous asset discovery, risk-based prioritization, and exposure management are well positioned to operationalize the directive’s four-variable model. Those still relying on periodic scanning and CVSS-based prioritization face a significant gap between current capability and compliance requirements.Background on CISA BOD 26-04On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, “Prioritizing Security Updates Based on Risk.” BOD 26-04 represents a fundamental shift in how federal agencies are expected to manage vulnerabilities. Rather than treating every known exploited vulnerability (KEV) with the same …