US federal deadlines
BOD 26-04 deadlines
As of , CISA has added 118 vulnerabilities to its list since BOD 26-04 took effect on ; 95 of them got a 3-day deadline.
What the directive says
CISA issued Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk", on 10 June 2026. It replaces BOD 19-02 and BOD 22-01 and binds US federal civilian agencies, not anyone else. Agencies must meet its timelines within 180 days of issue, by 7 December 2026.
Its Table 1 sets a deadline from four inputs: whether the vulnerable asset is exposed to the internet, whether the vulnerability is on CISA's list of exploited vulnerabilities, whether exploitation can be automated, and whether its technical impact is total or partial. For an entry on CISA's list the only timelines are 3 days with forensic triage, 3 days, or 14 days. CISA sets each entry's due date from the same table, so the due date now says how urgent CISA thinks the entry is.
- BOD 26-04 on cisa.govcisa.gov
- Implementation guidancecisa.gov
The deadlines CISA has set since
Table 1, the rows for entries on CISA's list
| Exposed to the internet | Automatable | Technical impact | Timeline |
|---|---|---|---|
| Yes | Yes | Total | 3 days and forensic triage |
| Yes | Yes | Partial | 3 days |
| Yes | No | Total | 3 days and forensic triage |
| Yes | No | Partial | 14 days |
| No | Yes | Total | 3 days and forensic triage |
| No | Yes | Partial | 14 days |
| No | No | Total | 14 days |
| No | No | Partial | 14 days |
The latest entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-102490Improper Privilege Management | Zammad GmbH Zammad | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-102489Session Fixation | Zammad GmbH Zammad | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-104286Path Traversal | Fortinet FortiMail | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| CVE-2026-76504Hex Encoding | Cisco Catalyst SD-WAN Manager | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| CVE-2026-86950Out-of-Bounds Write | Apple Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-88771Improper Input Validation | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-87902Remote File Inclusion | WordPress Core | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.46 | ||
| CVE-2026-67279Improper Enforcement of Behavioral Workflow | MikroTik RouterOS | Patch nowListed in the last 14 days | 0.01 | ||
| CVE-2026-65660Code Injection | Microsoft SharePoint | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| CVE-2026-71362Incorrect Authorization | Adobe Commerce and Magento | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.88 | ||
| CVE-2026-5430Path Traversal | WSO2 Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| CVE-2026-94127Heap-based Buffer Overflow | F5 BIG-IP APM | Patch nowForensic triage required by CISA | 0.02 | ||
| CVE-2026-93952Improper Input Validation | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-93616Path Traversal | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.20 | ||
| CVE-2026-85102Improper Certificate Validation | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.08 | ||
| CVE-2026-7273Stack-Based Buffer Overflow | Zyxel GS1900 Series Switches | Patch nowForensic triage required by CISA | 0.03 | ||
| CVE-2026-53266Out-of-Bounds Write | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2025-39964Race Condition | Linux Kernel | Patch nowForensic triage required by CISA | 0.01 |