LIVE NEWS
  • Women’s T20 World Cup: Danni Wyatt-Hodge on scoring ‘mummy’ hundred
  • Google unveils DiffusionGemma, an AI model that breaks free of left-to-right processing
  • Alaska’s glaciers have a startling response to rising temperatures
  • Blue state Dems accused of putting sanctuary policy over migrant child welfare checks
  • New proposal would close Medicare drug price negotiation loophole
  • Nvidia preps to sell its Vera CPUs into China as its GPU sales stay frozen — customers encouraged to place orders for CPU shipments as early as August
  • U.S. citizen arrested in China ID’d as Min Zin, Myanmar analyst : NPR
  • SPCX Solana Launch Same Day
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»CISA Orders Agencies to Patch by Risk, Not Severity
Cybersecurity

CISA Orders Agencies to Patch by Risk, Not Severity

primereportsBy primereportsJune 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
CISA Orders Agencies to Patch by Risk, Not Severity
Share
Facebook Twitter LinkedIn Pinterest Email


US federal agencies have been instructed to overhaul their vulnerability management practices, shifting away from rigid, deadline-driven patching toward a risk-based approach that prioritizes the most actively exploited threats, under new guidance from the Cybersecurity and Infrastructure Security Agency (CISA).

Binding Operational Directive 26-04, issued on June 10, ties each deadline to risk: three days, plus a forensic check for signs of intrusion, for the most dangerous flaws, with longer windows for less severe combinations and deferral for genuinely low-risk bugs, in some cases until a system’s next major upgrade. It consolidates two previous mandates, BOD 19-02 and the KEV-focused BOD 22-01.

CISA cast it as a response to a threat picture in which AI helps attackers find and weaponize bugs faster, shrinking defenders’ window once a patch ships, as the volume of disclosed flaws outpaces blanket patching.

The directive also pairs its tightest deadlines with a forensic step. When an agency patches the most serious flaws, it must check whether attackers have already exploited them, since a fix rarely evicts an intruder.

Read more on CISA directives: CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws

Risk Replaces the Severity Score

For years, CVSS severity scores drove prioritization, BOD 26-04 drops that. Revoking the old directive means agencies are no longer required to use CVSS to prioritize, since, as CISA noted, a severity label alone doesn’t dictate what to fix first.

The directive instead weighs four factors:

  • Asset exposure: whether the system is publicly reachable

  • KEV status: whether the flaw is on CISA’s Known Exploited Vulnerabilities (KEV) catalog

  • Exploit automation: whether an adversary can automate every step needed to exploit it

  • Technical impact: whether a successful attack grants partial or total control

Acting CISA director, Nick Andersen, said the directive lets agencies “focus their efforts on the areas of highest risk” and defer the rest. He urged private-sector and infrastructure operators to follow suit.

Doubts About the Execution

Agencies have 180 days, until around December 7, before they must meet the directive’s remediation timelines in every case. Practitioners broadly welcomed the aim while warning that the hard part is execution.

Knowing a bug is exploited, which the KEV catalog already flags, is only half the job, said Sunil Gottumukkala, CEO of agentic remediation platform provider Averlon. He said, “The other half is whether it matters in your environment.”

Denis Calderone, CTO of AI security firm Suzu Labs, agreed, “CVSS alone has never been a reliable way to decide which vulnerabilities to prioritize.” However, he questioned who will ensure agencies run real risk assessments rather than tick a compliance box, particularly given what he called deep cuts to CISA’s budget and workforce.

Calderone urged defenders to build their own stack now including KEV status, Exploit Prediction Scoring System (EPSS) probabilities and local context.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSpaceX IPO likely to break records : NPR
Next Article Analyst Benjamin Cowen Says Bitcoin Now in the Final Stage of the Bear Market – Here’s His Timeline
primereports
  • Website

Related Posts

Cybersecurity

Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security

June 12, 2026
Cybersecurity

In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine

June 12, 2026
Cybersecurity

Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Women’s T20 World Cup: Danni Wyatt-Hodge on scoring ‘mummy’ hundred
  • Google unveils DiffusionGemma, an AI model that breaks free of left-to-right processing
  • Alaska’s glaciers have a startling response to rising temperatures
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.