Bar chart showing the CISA remediation deadline median falling from 21 days in 2025 to 3 days in 2026
Fig. 1 — Median remediation deadline for newly added KEV entries (sources: CISA advisories, Stingrai analysis)

1. A 21-day deadline, compressed to three

On 10 June 2026, CISA issued BOD 26-04, "Prioritizing Security Updates Based on Risk," revoking both the 2021 BOD 22-01 and the 2019 BOD 19-02. The most vivid number in the change: the median remediation deadline for newly added entries in the CISA KEV (Known Exploited Vulnerabilities) catalogue fell from 21 days in 2025 to 3 days in 2026.

How could it be pushed that hard? Read the directive's risk matrix and the logic is clear. Under BOD 26-04 the deadline is no longer a fixed value but the output of four questions:

  1. Is the asset publicly exposed?
  2. Is the vulnerability already in the KEV catalogue?
  3. Can an adversary automate the exploit?
  4. Does exploitation yield partial or total control of the asset?

Stack those conditions and the resulting deadline ranges from 3 days to 14 days to 60 days to "whenever the system is next upgraded." The effect in practice is stark: of the 114 KEV entries added between 10 June and 1 October 2026, 91 (79.8%) carry a 3-day deadline and only 23 carry 14 days. Most entries now come with three days attached.

The directive also added a requirement that did not exist before: after remediating a high-risk vulnerability, a full forensic triage must determine whether the system was already compromised before the patch was applied. In other words, "patched" no longer means "handled."

Four-dimension risk matrix decision tree: public exposure, KEV listing, exploit automation and degree of control, yielding 3-day, 14-day and 60-day deadlines
Fig. 2 — The deadline is computed from four stacked questions, not fixed in advance

2. Why the change was needed: attacker speed has overtaken defender speed

The directive is not arbitrary. It follows from a set of difficult-to-ignore numbers.

Verizon's 2026 Data Breach Investigations Report tracked KEV remediation across more than 13,000 organisations: only 26% were fully remediated, with a median of 43 days, and 35% remained open at day 28. More pointed still, the survival analysis concludes that between 60% and 70% of KEV vulnerabilities are still open at day 7, regardless of year, volume or organisational maturity. BOD 26-04 allows three days. That is the gap.

There is a more disorienting number in Mandiant's M-Trends data: mean time to exploit is now negative seven days. That means exploitation frequently precedes public disclosure. Attackers hold better intelligence than defenders.

Weaponisation speed is rising too. Fortinet's response team reports attackers can turn a newly disclosed flaw into a working weapon in as little as 20 hours, while defenders take a median of 43 days to patch a known-exploited vulnerability. That 50-fold gap is the direct cause of this directive.

Volume is the other backdrop: roughly 59,000 CVEs are projected for 2026, more than 160 per day, with remote code execution flaws up 130% year on year. No process built around "one ticket per vulnerability" survives that rate.

CISA's own vulnerability review, published 26 August 2026, put it bluntly: most organisations continue to miss CISA's recommended remediation timelines. That sentence establishes the urgency — if agencies bound by demanding deadlines still miss them, organisations with no such requirement are plainly worse off.

The attacker-defender speed gap: fastest weaponisation 20 hours and mean time to exploit negative seven days, against a defender median of 43 days and the new 3-day deadline
Fig. 3 — The speed gap: 20 hours for an attacker, a 43-day median for defenders
Exposure list versus vulnerability list: on the left an unrankable mass of 974 items, on the right a handful of sortable public entry points
Fig. 4 — Build an exposure list, not a vulnerability list. Narrowing turns 974 into a dozen

3. It does not bind you, but the sorting method is free and worth taking

Scope first, to avoid misleading anyone: BOD 26-04 binds only US federal civilian agencies. It does not apply to Chinese organisations. CISA nonetheless encourages all organisations to adopt risk-based vulnerability management in its own advisories. There is also indirect reach: federal procurement (FedRAMP) requires mandatory adoption of vulnerability rules aligned with BOD 26-04 by 7 December 2026, so any supply chain that sells to US government bodies will eventually inherit the requirement.

Setting compliance aside, the method has real value for small businesses because it is a free prioritisation logic that answers "which of the 974 patches goes first". It maps directly onto the four-tier queue described in our previous article on the September Patch Tuesday:

BOD 26-04 dimensionWhat it means for you
Listed in KEVUnconditional top priority, 3 days
Publicly exposed plus total controlTreat as 3-day even if not in KEV
Exploit is automatableMove up to the 14-day tier
Not exposed, limited impactDefer to 60 days or the next maintenance window

The most counter-intuitive and most valuable element is that it explicitly concedes that not all vulnerabilities are equally urgent. For thirty years the industry default was that patch debt is bad. BOD 26-04 effectively says: accept that you cannot finish everything, and spend limited effort where it counts. Black Kite's vice president of cyber-risk strategy, Jeffrey Wheatman, puts it more bluntly — organisations should stop treating vulnerability management as a closed loop that ends in a patch, and instead continuously identify and reduce the exposures attackers are most likely to use.

Darktrace's senior vice president and field CISO Nicole Carignan offers a practical self-test: if the patch is two weeks late, does your organisation know it is exposed, what normal behaviour looks like, whether it can spot out-of-place activity, and whether it can respond or contain autonomously? If you cannot answer those four questions, the ordering debate is largely moot — what is actually missing is exposure visibility.

Binding scope versus methodology: BOD 26-04 binds only US federal agencies, while the risk-based prioritisation logic is open to any organisation
Fig. 6 — Borrow the method, not the mandate. Compliance is theirs; prioritisation is yours

4. Making this work at a 20-person company

Adopting BOD 26-04's logic does not require buying a single tool. It requires three concrete things:

  1. Build an exposure inventory, not a vulnerability list. Enumerate every inbound entry point the company has: public IPs, open ports, the systems running on them, and third-party-hosted management consoles. Before deciding how urgent a vulnerability is, check which line of that inventory it sits on. Once this is done, the overwhelming majority of the 974 CVEs are automatically downgraded.
  2. Make "is it internet-reachable?" the first question behind every security action. A CVSS 9.8 on a machine with no inbound traffic can wait a test cycle. The same flaw on a VPN gateway or a public RDP endpoint cannot. This judgement needs no tooling, yet it immediately changes the order of your team's schedule.
  3. Make "verify after patching" a fixed habit. The forensic triage BOD 26-04 now requires matters even more for small businesses, because nobody checks before patching. If a machine has been running Windows Server 2012 without CVE-2026-69730 applied and the patch is now installed, that does not prove it was never exploited. A log and credential audit at that point costs a fraction of investigating it after an incident.

A word against manufacturing anxiety: IBM's 2026 Cost of a Data Breach Report puts the global average breach cost at $4.99 million, up 12% year on year, but that figure reflects large multinationals and specific sectors and does not transfer directly to a forty-person company in Guangzhou. The more useful number is this one: mean time to identify and contain a breach reached 247 days, the first increase in five years after a run of steady improvement. That says something not only about faster attacks but about defenders' response chains lengthening in places. Which is why "asset inventory plus prioritisation" deserves more investment than "patch count".

The deadlines, risk dimensions and forensic-triage requirement described here were checked against CISA's BOD 26-04 directive (issued 10 June 2026) and its KEV catalogue updates through September and October 2026. Remediation-timeliness and exploitation-speed figures are drawn from Verizon's 2026 DBIR, Mandiant's 2026 M-Trends report and Fortinet's analysis; for accuracy, consult those source reports directly. One point must be stressed: BOD 26-04 binds only US federal civilian agencies and does not apply to domestic Chinese companies — what is offered here is its prioritisation methodology as a reference, not a compliance recommendation. If your organisation has assets with known active-exploitation risk, our articles on ransomware incident response order and server warning-light self-checks cover building out the surrounding process.

Three steps to make it routine: build the exposure inventory, make reachability the first question, and verify after every patch
Fig. 5 — Turning the method into routine. None of the three steps needs extra budget