Security2 distinct publishers3 min readPublished Updated
CISA has rewired the Known Exploited Vulnerabilities catalog to a binding directive issued June 10, 2026. The inclusion criteria are unchanged; the deadlines and the paperwork copying them are not.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CISA has updated its Known Exploited Vulnerabilities guidance page to point at Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk," issued on June 10, 2026 [1]. Federal civilian executive branch agencies now remediate KEV entries on the timeframes prescribed by that directive rather than under BOD 22-01 [3], and because a large share of private-sector remediation SLAs were written by copying the federal clock, a lot of internal policy text is now citing a superseded instrument.
The substance of the change is narrow but consequential. According to CISA, BOD 26-04 carries forward the KEV catalog criteria from BOD 22-01 and "integrates and harmonizes" the KEV with other patching timeline decision points [2]. Read plainly, that is two different statements. The intake pipeline is stable: a vulnerability still enters the catalog only when it has an assigned CVE ID, when there is reliable evidence of active exploitation in the wild, and when there is a clear remediation action such as a vendor-provided update [7]. What moved is the clock. KEV membership is no longer a standalone trigger sitting beside other patching rules; it is one decision point inside a harmonized set, under a directive whose title is about risk-based prioritization [1][2].
Note what the updated page does not do. It describes federal obligations only as remediation "within prescribed timeframes" and does not enumerate the specific BOD 26-04 timelines [10]. Anyone rewriting an SLA needs the directive text itself, not this page. If your policy says "remediate KEV within the CISA-mandated window," that sentence no longer resolves to a single number by way of the catalog alone.
For non-federal operators, the posture guidance is unchanged and still unambiguous. CISA says organizations outside the FCEB, including state, local, tribal and territorial government and private industry, are not bound by BOD 26-04 but strengthen their resilience by prioritizing KEV remediation [4], and it recommends that stakeholders include a requirement to immediately address KEV entries in their vulnerability management plans [5]. The catalog remains CISA's authoritative record of exploitation status and an input to prioritization frameworks such as SSVC, which consumes exploitation status as a factor [6]. CISA also recommends automated vulnerability and patch management tooling that flags or prioritizes KEV entries [8].
Three things to watch. First, whether your scanner and ticketing vendors change the semantics of any KEV due-date field they expose, since the federal timelines behind it have been reissued [3][8]. Second, contract and audit language: third-party questionnaires and regulated-sector requirements that name BOD 22-01 will drift out of date until they are amended [2]. Third, the upstream dependency, which has not changed and remains a single point of delay: nothing reaches KEV without a CVE ID assigned by a CNA, and CNA participation is voluntary [7][9].
Ranked by verification strength, evidence, and original report placement.
All federal civilian executive branch (FCEB) agencies are required to remediate vulnerabilities in the KEV catalog within prescribed timeframes under BOD 26-04.
CISA updated its "Reducing the Significant Risk of Known Exploited Vulnerabilities" page to reference Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, issued on June 10, 2026.
BOD 26-04 carries forward the KEV catalog criteria from BOD 22-01 and integrates and harmonizes the KEV with other patching timeline decision points.
Organizations not bound by BOD 26-04, including state, local, tribal, and territorial governments and private industry, can significantly strengthen their security and resilience posture by prioritizing remediation of vulnerabilities listed in the KEV catalog.
CISA strongly recommends all stakeholders include a requirement to immediately address KEV catalog vulnerabilities as part of their vulnerability management plan.
CISA maintains the KEV catalog as the authoritative source of vulnerabilities exploited in the wild, and says organizations should use it as an input to their vulnerability management prioritization framework; frameworks such as the Stakeholder-Specific Vulnerability Categorization (SSVC) model consider a vulnerability's exploitation status, for which the KEV catalog is the authoritative repository.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party and authoritative, but single-source
Every claim comes directly from the issuing agency's own guidance page, which is the authoritative publisher for both the KEV catalog and the directive reference — strong provenance for the fact that KEV is now tied to BOD 26-04 and that inclusion criteria are unchanged. Evidence is capped below high confidence because the cluster contains one source, the BOD 26-04 document itself is not supplied, and the operationally decisive detail (the actual remediation timeframes) is unstated.
Mandate documented, uptake unobserved
The only observable adoption is CISA's own guidance page being rebased to BOD 26-04, plus the directive's stated binding scope over all FCEB agencies. There is no evidence in the cluster of agency compliance rates, tooling updates that reference the new directive, or non-federal organizations revising their vulnerability management plans, so real-world uptake cannot be scored higher.
Understated relative to compliance impact
The source language is plain regulatory prose with no promotional framing: a one-line update notice re-points the KEV catalog's enforcement authority and asserts continuity of criteria. Given that the change invalidates directive citations embedded across patch SLAs and vulnerability management documentation, the presentation is modestly understated rather than overstated. The gap is small because the story's own claims stay within what the primary source says and do not assert deadline values the page omits.
Agency self-publication of its own directive
The single source is the agency that issues the directive, sponsors the CVE Program, and maintains the KEV catalog, so it has an institutional interest in presenting KEV as the authoritative exploitation repository and in encouraging voluntary adoption beyond its mandate. This is disclosed, non-commercial, primary-source self-interest rather than hidden or revenue-driven promotion, so the distortion risk is moderate; no vendor or investor incentives are documented in the cluster.
High on the fact, low on the operative detail
Confidence is high that the KEV catalog's federal hook is now BOD 26-04 and that inclusion criteria are unchanged, because the authoritative publisher says so directly. Confidence is materially lower on the operational implication that drives the story — what the new timelines actually are and how they differ from BOD 22-01 — because the directive text is absent, no second publisher corroborates, and no compliance evidence exists.
security
CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass4 distinct publishers
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
product
CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines1 distinct publisher
security
CISA asks buyers to make eliminated vulnerability classes a contract condition1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026
1 article · August 20, 2026