Skip to content

standard

Binding Operational Directive 26-04

CISA directive on prioritizing security updates based on risk; requires that an adequate forensic triage analysis be performed, with recommended KEV-triggered timelines.

Known aliases

  • Binding Operational Directive 26-04
  • BOD 26-04
  • Prioritizing Security Updates Based on Risk

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

NetScaler compromise response has to unwind the controls the gateway concentrated

Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence55
security4 publishers

CISA puts Ray on the KEV list, and the exploit path runs through your developers' browsers

CVE-2025-62593 carries a CVSS 9.4 and a federal remediation deadline of August 20, 2026. The unauthenticated endpoints behind it are a design decision, not an oversight.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 60%
Investor
Investor 6%

Reality

Evidence68
Adoption50
Hype gap+15
Incentives35
Confidence66
security5 publishers

Exploited within hours: MLflow SSRF and FUXA auth bypass join the emergency patch list

watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 63%
Investor
Investor 8%

Reality

Evidence72
Adoption55
Hype gap+20
Incentives35
Confidence70
security4 publishers

Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check

CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 68%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence70
security7 publishers

Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.

Perspective Coverage

7 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence78
Adoption50
Hype gap−40
Incentives
Insufficient
Confidence74
security7 publishers

Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.

Perspective Coverage

7 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption40
Hype gap+20
Incentives
Insufficient
Confidence58
security4 publishers

CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.

Perspective Coverage

4 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence66
security4 publishers

A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security13 publishers

CISA sets a September 13 deadline for the MikroTrick RouterOS chain

Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.

Perspective Coverage

13 publishers
Builder
Builder 21%
Operator
Operator 76%
Investor
Investor 3%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence66
security6 publishers

CISA gives agencies one business day to patch three exploited Linux kernel flaws

The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.

Perspective Coverage

6 publishers
Builder
Builder 30%
Operator
Operator 57%
Investor
Investor 13%

Reality

Evidence74
Adoption68
Hype gap−8
Incentives38
Confidence76
security16 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

16 publishers
Builder
Builder 18%
Operator
Operator 64%
Investor
Investor 18%

Reality

Evidence82
Adoption58
Hype gap−8
Incentives62
Confidence80

Earlier coverage

  1. FedRAMP's staffing conditions make federal SaaS revenue a hiring decision

    Leadership · September 17, 2026 · 1 publisher

  2. Confirmed exploitation now lands 40 days sooner after a CVE goes public

    Product · September 15, 2026 · 1 publisher

  3. Attackers have been pushing VBScript through live ScreenConnect sessions since August 20

    Security · September 14, 2026 · 1 publisher

  4. CISA mirrors the KEV catalog on GitHub with a public commit history

    Security · September 12, 2026 · 1 publisher

  5. Attackers have been planting web shells on Magento stores since September 4

    Security · September 10, 2026 · 2 publishers

  6. Gitea's unpatched older branches force migration to 1.27.x as CISA flags active exploitation

    Leadership · September 5, 2026 · 1 publisher

  7. Unauthenticated file exposure puts ownCloud first in CISA's newest KEV batch

    Leadership · September 4, 2026 · 1 publisher

  8. CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines

    Product · August 18, 2026 · 1 publisher

  9. CISA's KEV triage guidance tells agencies to collect RAM before they patch

    Security · August 17, 2026 · 1 publisher