Skip to content

Security1 publisher2 min readPublished

CISA updates KEV catalog page to reference new directive BOD 26-04

The directive issued June 10, 2026 keeps the KEV catalog's three inclusion criteria and folds federal remediation deadlines into a wider patching timeline. Any policy that cites BOD 22-01 now names a superseded authority.

The Watch · Security desk

Illustration accompanying CISA updates KEV catalog page to reference new directive BOD 26-04

What happened

  • CISA updated its Known Exploited Vulnerabilities page to reference Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, which was issued on June 10, 2026.
  • CISA says the new directive carries the KEV catalog criteria over from BOD 22-01 and integrates the catalog with other patching timeline decision points.
  • State, local, tribal and territorial governments and private industry are not bound by BOD 26-04, and CISA restated its recommendation that they prioritize KEV remediation anyway.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Anyone whose vulnerability management standard names BOD 22-01 as the source of its KEV clock has to choose a replacement citation, and the figure that goes with it is not on CISA's page yet.
  • cost The bill here is documentation review, because the catalog criteria carried forward and KEV-aware scanning and patch tooling is untouched.
  • constraint Federal teams lose the option of running a KEV due date as a self-contained countdown, since the directive folds it in with other patching decision points.
  • exposure Suppliers held to KEV deadlines by a contract clause that incorporates BOD 22-01 are being measured against an authority CISA has replaced for federal use.

A vulnerability management standard that tells staff to remediate KEV entries within the timeframes set by BOD 22-01 now cites a directive CISA's own KEV page no longer treats as the governing authority [1][3].

The catalog itself stayed put. An entry still requires an assigned CVE ID, reliable evidence that the vulnerability has been actively exploited in the wild, and a clear remediation action such as a vendor-provided update [5]. CISA says BOD 26-04 carries forward the KEV catalog criteria from BOD 22-01 [2]. Scanners and patch pipelines that flag KEV entries keep working as they did [10].

CISA describes 26-04 as integrating and harmonizing "the KEV with other patching timeline decision points" [2]. Under it, all federal civilian executive branch agencies are required to remediate KEV vulnerabilities within prescribed timeframes [3]. The page does not print those timeframes, and it does not say whether 22-01 has been rescinded [4].

For everyone else the edit is to the paperwork. CISA repeats that state, local, tribal and territorial governments and private industry are not bound by 26-04 [6]. It still recommends that all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan [7]. The page also puts the catalog one step back in the chain, as an input to a prioritization framework such as SSVC, which considers a vulnerability's exploitation status [8]. It points at automated vulnerability and patch management tools that flag or prioritize KEV entries [9]. A private-sector SLA that pegged itself to the federal KEV window has to wait for 26-04's timeframes to be published [4][6].

An attacker's reach this week is the same as it was. A KEV listing has always meant exploitation observed in the wild with a remediation available [5], and that holds across the directive swap. The rework is clerical. CISA has not published the number that goes with it, and every policy or contract clause that names BOD 22-01 as the source of a KEV deadline needs a new citation [4].

What to watch

  • Publication of the BOD 26-04 text with the prescribed remediation timeframes for KEV entries.
  • Any CISA statement on the current status of BOD 22-01.
  • Whether CISA's guidance for automated patch tooling is revised to match the harmonized timeline.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories