Skip to content

standard

BOD 22-01

CISA directive requiring U.S. federal civilian agencies to remediate vulnerabilities listed in its Known Exploited Vulnerabilities catalog within set deadlines.

Known aliases

  • Binding Operational Directive 22-01
  • BOD 22-01
  • Reducing the Significant Risk of Known Exploited Vulnerabilities

Relationships

No evidence-backed relationships are recorded.

Current stories

security4 publishers

Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check

CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 68%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence70
security4 publishers

CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.

Perspective Coverage

4 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence66
security4 publishers

A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security6 publishers

CISA gives agencies one business day to patch three exploited Linux kernel flaws

The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.

Perspective Coverage

6 publishers
Builder
Builder 30%
Operator
Operator 57%
Investor
Investor 13%

Reality

Evidence74
Adoption68
Hype gap−8
Incentives38
Confidence76