Skip to content

Security1 publisher3 min readPublished

Operators rebuilding CISA's post-CVSS patch sort must merge KEV with Vulnrichment themselves

BOD 26-04 revoked the federal CVSS requirement on June 10. The two decision fields CISA promised, automatability and technical impact, go out through Vulnrichment; the KEV feed does not carry them, so every defender does the join.

The Watch · Security desk

Illustration accompanying Operators rebuilding CISA's post-CVSS patch sort must merge KEV with Vulnrichment themselves

What happened

  • BOD 26-04 took effect June 10, revoking BOD 22-01 and ending the federal requirement that agencies prioritize vulnerability remediation by CVSS score.
  • Verizon's 2026 Data Breach Investigations Report puts full KEV remediation at 26 percent for 2025, down from 38 percent, with median time to resolution up to 43 days from 32.
  • CISA's commit history records 112 silent flips of the KEV ransomware field to "Known" since January 2025, at a median of about 360 days after the entry was first listed.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost The two fields the directive promises, automatability and technical impact, go out through Vulnrichment, so each defender who wants the federal sort builds and maintains the join into the KEV feed at their own expense.
  • constraint Changes to the ransomware field go out unannounced, so keeping current on it requires storing and diffing daily snapshots of a federal data source.
  • decision A KEV entry on an internet-facing edge device changes the ticket type: the work starts as a hunt and a credential rotation, and the patch closes the ticket without answering it.
  • exposure Because exposure is the input only the operator holds, the same CVE carries a different deadline in two estates, and an asset moved onto the internet reprioritizes itself.

The replacement sort has three inputs, and one of them ships in the KEV feed. BOD 26-04 commits CISA to publishing automatability and technical impact for every KEV entry. That data goes out through the Vulnrichment program, and the KEV feed's 12 fields carry neither [5]. Anyone who wants the federal sort does the join. The third input is exposure, which the operator holds, and it moves a deadline in both directions as an asset goes onto the internet or comes off it [6].

Verizon's 2026 Data Breach Investigations Report puts full KEV remediation at 26 percent for 2025, down from 38 percent, with median time to resolution up to 43 days from 32 [3]. That is 12 percentage points off the completion rate [4] and 11 days added to the median [11]. Any single organization runs a small share of the catalog, which over the same period reached 1,705 entries on Sept. 10, 2026, spanning 283 vendors and 719 product listings [2].

The ransomware field is the weakest part of the feed for triage. CISA's commit history records 112 silent flips to "Known" since January 2025, at a median of about 360 days after the entry was listed, according to Collin Hogue-Spears of Black Duck, who wrote the column [7]. Roughly half of those flips landed more than a year after the entry appeared, none carried an alert, and finding them has meant diffing daily snapshots of a federal data source [8]. A flip records an attack that already happened [9].

Top-tier work on an exposed edge device is an investigation with a patch at the end: hunt for evidence of exploitation, review authentication activity, rotate the credentials and tokens the device held, and confirm attackers left no persistence [10]. On the WatchGuard Firebox flaw CISA flagged this month, WatchGuard documented theft of the device configuration and the local user database [12]. "Patching in January does not recover the credentials stolen in December," Hogue-Spears wrote [13].

His three asks of CISA are a date on the ransomware field plus a change feed for every edit to it, the decision data inside the KEV feed itself, and an exploitation-recency signal such as a last-observed date [14]. That signal separates historical KEV status from a campaign still producing telemetry. The first two exist to remove work defenders are doing by hand. The 112 flips over the roughly 20 months from January 2025 to Sept. 10, 2026 work out to about six a month, and only a snapshot diff would catch them [15]. This is one practitioner's column. CISA did not publish it. The data-quality complaint has a simple demonstration in the catalog itself: entries added in late 2025 still send readers to BOD 22-01, revoked in June [16].

What to watch

  • Whether CISA puts automatability and technical impact into the KEV feed's own fields, as BOD 26-04 commits it to publishing them.
  • Whether the ransomware field gains a date and a published change feed, which would end the daily snapshot diffing.
  • Whether Verizon's 2027 DBIR shows the 26 percent completion rate recovering or the 43-day median stretching further.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories