Published · 3d agoSecurity3 min read
CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CISA updated its "Reducing the Significant Risk of Known Exploited Vulnerabilities" page to reference Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, issued on June 10, 2026.
- BOD 26-04 carries forward the KEV catalog criteria from BOD 22-01 and integrates and harmonizes the KEV with other patching timeline decision points.
- All federal civilian executive branch (FCEB) agencies are required to remediate vulnerabilities in the KEV catalog within prescribed timeframes under BOD 26-04.
- Organizations not bound by BOD 26-04, including state, local, tribal, and territorial governments and private industry, can significantly strengthen their security and resilience posture by prioritizing remediation of vulnerabilities listed in the KEV catalog.
- CISA strongly recommends all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA has updated its Known Exploited Vulnerabilities guidance page to point at Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk," issued on June 10, 2026 [1]. Federal civilian executive branch agencies now remediate KEV entries on the timeframes prescribed by that directive rather than under BOD 22-01 [3], and because a large share of private-sector remediation SLAs were written by copying the federal clock, a lot of internal policy text is now citing a superseded instrument.
The substance of the change is narrow but consequential. According to CISA, BOD 26-04 carries forward the KEV catalog criteria from BOD 22-01 and "integrates and harmonizes" the KEV with other patching timeline decision points [2]. Read plainly, that is two different statements. The intake pipeline is stable: a vulnerability still enters the catalog only when it has an assigned CVE ID, when there is reliable evidence of active exploitation in the wild, and when there is a clear remediation action such as a vendor-provided update [7]. What moved is the clock. KEV membership is no longer a standalone trigger sitting beside other patching rules; it is one decision point inside a harmonized set, under a directive whose title is about risk-based prioritization [1][2].
Note what the updated page does not do. It describes federal obligations only as remediation "within prescribed timeframes" and does not enumerate the specific BOD 26-04 timelines [10]. Anyone rewriting an SLA needs the directive text itself, not this page. If your policy says "remediate KEV within the CISA-mandated window," that sentence no longer resolves to a single number by way of the catalog alone.
For non-federal operators, the posture guidance is unchanged and still unambiguous. CISA says organizations outside the FCEB, including state, local, tribal and territorial government and private industry, are not bound by BOD 26-04 but strengthen their resilience by prioritizing KEV remediation [4], and it recommends that stakeholders include a requirement to immediately address KEV entries in their vulnerability management plans [5]. The catalog remains CISA's authoritative record of exploitation status and an input to prioritization frameworks such as SSVC, which consumes exploitation status as a factor [6]. CISA also recommends automated vulnerability and patch management tooling that flags or prioritizes KEV entries [8].
Three things to watch. First, whether your scanner and ticketing vendors change the semantics of any KEV due-date field they expose, since the federal timelines behind it have been reissued [3][8]. Second, contract and audit language: third-party questionnaires and regulated-sector requirements that name BOD 22-01 will drift out of date until they are amended [2]. Third, the upstream dependency, which has not changed and remains a single point of delay: nothing reaches KEV without a CVE ID assigned by a CNA, and CNA participation is voluntary [7][9].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA updated its "Reducing the Significant Risk of Known Exploited Vulnerabilities" page to reference Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, issued on June 10, 2026.
- [2]
BOD 26-04 carries forward the KEV catalog criteria from BOD 22-01 and integrates and harmonizes the KEV with other patching timeline decision points.
- [3]
All federal civilian executive branch (FCEB) agencies are required to remediate vulnerabilities in the KEV catalog within prescribed timeframes under BOD 26-04.
- [4]
Organizations not bound by BOD 26-04, including state, local, tribal, and territorial governments and private industry, can significantly strengthen their security and resilience posture by prioritizing remediation of vulnerabilities listed in the KEV catalog.
- [5]
CISA strongly recommends all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan.
- [6]
CISA maintains the KEV catalog as the authoritative source of vulnerabilities exploited in the wild, and says organizations should use it as an input to their vulnerability management prioritization framework; frameworks such as the Stakeholder-Specific Vulnerability Categorization (SSVC) model consider a vulnerability's exploitation status, for which the KEV catalog is the authoritative repository.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- orca.securityJake Kramber3d agoBOD 26-04 Just Changed How Federal Agencies Prioritize Vulnerabilities.
Additional citations
- CISA



