US federal deadlines

BOD 26-04 deadlines

As of , CISA has added 118 vulnerabilities to its list since BOD 26-04 took effect on ; 95 of them got a 3-day deadline.

What the directive says

CISA issued Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk", on 10 June 2026. It replaces BOD 19-02 and BOD 22-01 and binds US federal civilian agencies, not anyone else. Agencies must meet its timelines within 180 days of issue, by 7 December 2026.

Its Table 1 sets a deadline from four inputs: whether the vulnerable asset is exposed to the internet, whether the vulnerability is on CISA's list of exploited vulnerabilities, whether exploitation can be automated, and whether its technical impact is total or partial. For an entry on CISA's list the only timelines are 3 days with forensic triage, 3 days, or 14 days. CISA sets each entry's due date from the same table, so the due date now says how urgent CISA thinks the entry is.

The deadlines CISA has set since

  1. 3 days and forensic triage75
  2. 3 days20
  3. 14 days23
Entries CISA added since 10 June 2026, by the days from listing to the due date. Source: CISA KEV.

Table 1, the rows for entries on CISA's list

From BOD 26-04 Table 1, Remediation Timelines, as read on cisa.gov on 1 October 2026; calendar days.
Exposed to the internetAutomatableTechnical impactTimeline
YesYesTotal3 days and forensic triage
YesYesPartial3 days
YesNoTotal3 days and forensic triage
YesNoPartial14 days
NoYesTotal3 days and forensic triage
NoYesPartial14 days
NoNoTotal14 days
NoNoPartial14 days

The latest entries

The latest entries
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-102490Improper Privilege ManagementZammad GmbH ZammadPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-102489Session FixationZammad GmbH ZammadPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-104286Path TraversalFortinet FortiMailPatch nowForensic triage required by CISA; listed in the last 14 days0.02
CVE-2026-76504Hex EncodingCisco Catalyst SD-WAN ManagerPatch nowForensic triage required by CISA; listed in the last 14 days0.02
CVE-2026-86950Out-of-Bounds WriteApple Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-88771Improper Input ValidationCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-87902Remote File InclusionWordPress CorePatch nowForensic triage required by CISA; listed in the last 14 days0.46
CVE-2026-67279Improper Enforcement of Behavioral WorkflowMikroTik RouterOSPatch nowListed in the last 14 days0.01
CVE-2026-65660Code InjectionMicrosoft SharePointPatch nowForensic triage required by CISA; listed in the last 14 days0.02
CVE-2026-71362Incorrect AuthorizationAdobe Commerce and MagentoPatch nowForensic triage required by CISA; listed in the last 14 days0.88
CVE-2026-5430Path TraversalWSO2 Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
CVE-2026-94127Heap-based Buffer OverflowF5 BIG-IP APMPatch nowForensic triage required by CISA0.02
CVE-2026-93952Improper Input ValidationArista VeloCloud OrchestratorPatch nowForensic triage required by CISA0.01
CVE-2026-93616Path TraversalCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.20
CVE-2026-85102Improper Certificate ValidationCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.08
CVE-2026-7273Stack-Based Buffer OverflowZyxel GS1900 Series SwitchesPatch nowForensic triage required by CISA0.03
CVE-2026-53266Out-of-Bounds WriteLinux KernelPatch nowForensic triage required by CISA0.01
CVE-2025-39964Race ConditionLinux KernelPatch nowForensic triage required by CISA0.01

Every day CISA added to its list