CISA tells govt agencies to patch critical exploited flaws in 3 days

CISA tells govt agencies to patch critical exploited flaws in 3 days — Cybersecurity | Versia.media

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new Binding Operational Directive, 26-04, which emphasizes security updates for Federal Civilian Executive Branch (FCEB) agencies.

This directive is designed to mitigate the risk of cyberattacks on the public sector by mandating that agencies address high-risk vulnerabilities within shortened deadlines, occasionally as brief as three days.

According to CISA, BOD 26-04 “supersedes and revokes” the earlier BOD 19-02 and BOD 22-01, which were introduced in 2019 and 2021, respectively.

The agency states that prioritizing patches is guided by four key factors:

Whether the asset is accessible online to the public

Inclusion of the vulnerability in CISA’s Known Exploited Vulnerabilities (KEV) catalog

If exploitation can be automated for widespread attacks

Whether exploitation grants attackers partial or complete control over a system

Based on these criteria, agencies are given deadlines for fixing security vulnerabilities, with the shortest period being three days.

For less critical scenarios where automated exploitation is unfeasible or only allows partial control, the timeline is set at two weeks.

Scope and implementation

The directive specifically targets U.S. Federal Civilian Executive Branch (FCEB) agencies and the information systems they manage.

This includes government agencies and departments, but excludes certain military systems run by the U.S. Department of Defense, private firms, Intelligence Community systems, and contractors.

Similar to previous directives, this framework is anticipated to shape the broader cybersecurity sector and offer a more defined patching priority indicator.

The directive covers all on-premises federal systems, third-party hosted systems, and FedRAMP/non-FedRAMP cloud environments.

Currently, agencies subject to BOD 26-04 should revise their vulnerability management policies accordingly, update their asset inventories, and automate KEV status reporting.

Vulnerability management processes must be updated within 60 days to use CVE and KEV data as the foundation for remediation decisions.

Within 180 days, all agencies will need to adhere to the new remediation timelines and continuously monitor and report detailed asset metadata.

Test every layer before attackers do

Security teams detect 54% of successful attacks and issue alerts for only 14%. The remainder moves through your environment unnoticed.

The Picus whitepaper demonstrates how breach and attack simulation evaluates your SIEM and EDR rules to prevent threats from evading detection.

Related Articles:

CISA orders feds to patch actively exploited Ivanti flaw by Sunday

GM agrees to $12.75M California settlement over sale of drivers’ data

CISA orders feds to patch exploited Ivanti EPMM flaw by Saturday

CISA flags new SD-WAN flaw as actively exploited in attacks

CISA gives feds three days to patch Ivanti flaw exploited as zero-day

← Cybersecurity