CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
CISA issued BOD 26-04, which replaces BOD 22-01 with a four-variable vulnerability prioritization model requiring federal agencies to patch the most dangerous vulnerabilities in as few as three days. Key takeaways BOD 26-04 replaces BOD 22-01 with a four-variable risk model that assigns graduated remediation timelines, from as few as three days with mandatory forensic triage for the most dangerous vulnerabilities to full deferral for the lowest-risk ones, ending the era of flat, one-size-fits-all patching deadlines for federal agencies. The transition represents a significant operational lift at a time when AI is compressing the window between vulnerability disclosure and weaponization, and industry remediation rates are declining: only 26% of KEV vulnerabilities were fully remediated in 2025 according to the 2026 Verizon DBIR, down from 38% the prior year. Organizations that have invested in continuous asset discovery, risk-based prioritization, and exposure management are well positioned to operationalize the directive’s four-variable model. Those still relying on periodic scanning and CVSS-based prioritization face a significant gap between current capability and compliance requirements. Background on CISA BOD 26-04 On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, “Prioritizing Security Updates Based on Risk.” BOD 26-04 represents a fundamental shift in how federal agencies are expected to manage vulnerabilities. Rather than treating every known exploited vulnerability (KEV) with the same remediation deadline, the new directive introduces a graduated model that accounts for asset exposure, exploitation evidence, adversary automation capability, and technical impact severity. The result is a 16-tier remediation matrix where the most dangerous vulnerabilities must be patched within three days (with mandatory forensic triage), while lower-risk vulnerabilities can be deferred to the next system upgrade cycle. Tenable applauds this directive, which replaces both BOD 22-01 (Reducing the Significant Risk of Known Exploited Vulnerabilities, November 2021) and BOD 19-02 (Vulnerability Remediation Requirements for Internet-Accessible Systems, April 2019). It is directionally correct in Tenable’s view, and it represents a significant improvement upon its predecessors, as it consolidates seven years of federal vulnerability remediation policy into a single, risk-weighted framework. More importantly, it aligns with the risk-based, exposure-driven approach to vulnerability management that Tenable has championed as the originator of the exposure management paradigm. For years, Tenable has maintained the position that defenders must move beyond volume-based patching toward intelligent prioritization grounded in real-world exploitation evidence, asset context, and threat actor intelligence. BOD 26-04 codifies that position as federal policy. Frequently asked questions about BOD 26-04 What is BOD 26-04? BOD 26-04 is a binding operational directive from CISA that requires all Federal Civilian Executive Branch (FCEB) agencies to prioritize vulnerability remediation based on a four-variable risk model. Unlike its predecessor BOD 22-01, which assigned flat remediation timelines to all vulnerabilities in the KEV catalog, BOD 26-04 evaluates each vulnerability against four criteria and assigns a remediation deadline based on the specific combination of risk factors present. The directive is mandatory for federal agencies but not for the private sector. However, CISA explicitly encourages private sector adoption, and the track record of BOD 22-01 suggests the framework will become a de facto standard across industries. BOD 22-01’s KEV catalog is already used by organizations worldwide as a prioritization signal, and BOD 26-04’s more sophisticated model will likely follow the same adoption curve. What are the four variables? BOD 26-04 determines remediation urgency using four binary variables: Publicly exposed - Is the vulnerable asset reachable from outside the agency network via a routable IP address? This is the only variable agencies must determine themselves. In the KEV - Is the CVE listed in CISA’s Known Exploited Vulnerabilities catalog? This confirms real-world exploitation. Automatable by adversary - Can an attacker automate all the steps necessary to exploit the vulnerability? This assesses weaponization maturity. Technical impact - Does exploitation give attackers total control of the affected system or only partial control? CISA publishes the answers to variables two, three, and four for every CVE through its Vulnrichment Program. Agencies must determine variable one (public exposure) using their own asset inventory and CISA’s Internet Exposure Reduction Guidance. What are the remediation timelines? Table 1 in Appendix A of the directive maps all 16 possible combinations of the four binary variables to specific remediation deadlines across five tiers: Three days with forensic triage - Required when a vulnerability is in the KEV and yields total system control (regardless of whether the asset is publicly exposed or the exploit is automatable). This is the most aggressive vulnerability management timeline in federal directive history. The forensic triage component requires agencies to assess whether their systems have already been compromised. Three days (without forensic triage) - Required for certain high-risk combinations, such as a publicly exposed asset with an automatable vulnerability yielding total control, even if the CVE is not yet in the KEV. 14 days - The standard accelerated timeline for most KEV-listed vulnerabilities and several high-risk non-KEV combinations. 60 days - Applied to lower-risk combinations, such as non-exposed assets with automatable but partial-control vulnerabilities. Fix on system upgrade - Applied when no risk criteria are met. This is the deferral tier, and it represents a significant operational relief for agencies: vulnerabilities that meet none of the four criteria can wait for the next scheduled upgrade cycle. Timelines are dynamic. If an agency removes a system from public internet exposure, the applicable timeline shifts to a longer window. Conversely, if CISA adds a vulnerability to the KEV catalog, the remediation timeline accelerates immediately. In an initial analysis at one large civilian agency, CISA found that only 1% of vulnerability instances fell into the three-day category, while over 60% qualified for deferral to the next system upgrade. The model is designed to focus resources, not overwhelm them. What changed from BOD 22-01? BOD 26-04 revokes and replaces BOD 22-01 entirely. The key differences are substantial: BOD 22-01 applied a flat remediation timeline to every vulnerability in the KEV catalog (14 days for CVEs assigned after 2021, six months for older CVEs). BOD 26-04 replaces this with a graduated model where KEV status is one of four variables, not the sole determinant of urgency. A KEV vulnerability on an internal system with partial control and no automation capability now receives 14 days, while the same KEV on a publicly exposed system with full automation and total control receives just three days with mandatory forensic triage. BOD 22-01 had no deferral mechanism. Every KEV required action. BOD 26-04 introduces the “fix on system upgrade” tier for vulnerabilities that meet none of the four risk criteria, allowing agencies to focus on the ones that matter most rather than chasing every vulnerability with equal urgency. BOD 22-01 had no forensic triage requirement. BOD 26-04 introduces mandatory forensic analysis for the highest-risk tier, recognizing that when a vulnerability is actively exploited and yields total system control, patching alone is insufficient: organizations need to determine whether they’ve been compromised. The underlying methodology also shifts. BOD 22-01 relied primarily on the KEV catalog and CVSS scoring. BOD 26-04 is informed by CISA’s Stakeholder-Specific Vulnerability Categorization (SSVC) system, which provides a more nuanced, risk-informed vulnerability analysis methodology. Why did CISA issue BOD 26-04 now? Two converging factors drove the directive. The first is the deteriorating effectiveness of traditional vulnerability management. Citing the 2026 Verizon Data Breach Investigations Report, CISA’s blog post accompanying the directive notes that only 26% of KEV-listed vulnerabilities were fully remediated by organizations in 2025, a decline from 38% the previous year. Meanwhile, the median time to fully resolve vulnerabilities rose to 43 days. In an environment where exploitation can occur within hours of disclosure, the remediation gap is widening. The second factor is artificial intelligence. CISA explicitly states that AI is accelerating both vulnerability discovery and weaponization, narrowing the window of time that exists between vulnerability disclosure and exploitation. The directive aligns with priorities in the recent AI Executive Order , Promoting Advanced Artificial Intelligence Innovation and Security . As AI-enabled tools make it easier for adversaries to identify, weaponize, and deploy exploits at scale, the traditional “patch everything eventually” approach becomes untenable. Defenders need a framework that tells them what to patch first, and BOD 26-04 provides the framework enabling them to prioritize on an accelerated timeframe. This is a challenge Tenable has been tracking closely. The intersection of an AI-enabled threat landscape with already-declining remediation effectiveness creates a compounding problem: adversaries are getting faster while defenders fall farther behind. BOD 26-04 is a necessary policy response to this environment. I don’t work for a federal agency. How does BOD 26-04 affect my organization? While BOD 26-04 is mandatory only for FCEB agencies, its influence extends well beyond the federal government. BOD 22-
AI Analysis
Technical Summary
CISA's BOD 26-04 mandates federal agencies to prioritize vulnerability remediation based on a four-variable risk model: public exposure, presence in the Known Exploited Vulnerabilities (KEV) catalog, adversary automation capability, and technical impact severity. This model creates 16 risk tiers with corresponding remediation deadlines, from three days with forensic triage for the highest risk vulnerabilities to deferral for the lowest risk. The directive replaces BOD 22-01's flat remediation timelines and introduces forensic triage requirements for critical vulnerabilities. It addresses challenges posed by AI-accelerated vulnerability discovery and exploitation, aiming to focus resources on the most dangerous vulnerabilities. The directive is mandatory for federal civilian agencies but is expected to influence private sector practices. It consolidates prior federal vulnerability policies into a single, risk-weighted framework aligned with modern exposure management principles.
Potential Impact
The directive changes federal vulnerability management by enforcing accelerated patching for the most dangerous vulnerabilities, including mandatory forensic triage to detect potential compromises. It aims to reduce the window of exposure to critical vulnerabilities, especially those that are publicly exposed, automatable by adversaries, and yield total system control. This graduated approach helps agencies focus remediation efforts on vulnerabilities that pose the greatest risk, potentially reducing successful exploitations and improving overall cybersecurity posture. The policy also acknowledges the increasing speed of exploitation driven by AI, addressing the widening remediation gap observed in recent years.
Mitigation Recommendations
BOD 26-04 itself is a policy directive rather than a vulnerability with a patch. Federal agencies must implement the four-variable risk model to prioritize vulnerability remediation according to the directive's timelines. Agencies should maintain accurate asset inventories to determine public exposure status and follow CISA's Internet Exposure Reduction Guidance. For the highest-risk vulnerabilities, agencies must conduct forensic triage to assess potential compromises. Organizations outside the federal government are encouraged to adopt similar risk-based prioritization frameworks. There is no patch or fix to apply for this directive; rather, compliance involves operational changes in vulnerability management processes.
CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
Description
CISA issued BOD 26-04, which replaces BOD 22-01 with a four-variable vulnerability prioritization model requiring federal agencies to patch the most dangerous vulnerabilities in as few as three days. Key takeaways BOD 26-04 replaces BOD 22-01 with a four-variable risk model that assigns graduated remediation timelines, from as few as three days with mandatory forensic triage for the most dangerous vulnerabilities to full deferral for the lowest-risk ones, ending the era of flat, one-size-fits-all patching deadlines for federal agencies. The transition represents a significant operational lift at a time when AI is compressing the window between vulnerability disclosure and weaponization, and industry remediation rates are declining: only 26% of KEV vulnerabilities were fully remediated in 2025 according to the 2026 Verizon DBIR, down from 38% the prior year. Organizations that have invested in continuous asset discovery, risk-based prioritization, and exposure management are well positioned to operationalize the directive’s four-variable model. Those still relying on periodic scanning and CVSS-based prioritization face a significant gap between current capability and compliance requirements. Background on CISA BOD 26-04 On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, “Prioritizing Security Updates Based on Risk.” BOD 26-04 represents a fundamental shift in how federal agencies are expected to manage vulnerabilities. Rather than treating every known exploited vulnerability (KEV) with the same remediation deadline, the new directive introduces a graduated model that accounts for asset exposure, exploitation evidence, adversary automation capability, and technical impact severity. The result is a 16-tier remediation matrix where the most dangerous vulnerabilities must be patched within three days (with mandatory forensic triage), while lower-risk vulnerabilities can be deferred to the next system upgrade cycle. Tenable applauds this directive, which replaces both BOD 22-01 (Reducing the Significant Risk of Known Exploited Vulnerabilities, November 2021) and BOD 19-02 (Vulnerability Remediation Requirements for Internet-Accessible Systems, April 2019). It is directionally correct in Tenable’s view, and it represents a significant improvement upon its predecessors, as it consolidates seven years of federal vulnerability remediation policy into a single, risk-weighted framework. More importantly, it aligns with the risk-based, exposure-driven approach to vulnerability management that Tenable has championed as the originator of the exposure management paradigm. For years, Tenable has maintained the position that defenders must move beyond volume-based patching toward intelligent prioritization grounded in real-world exploitation evidence, asset context, and threat actor intelligence. BOD 26-04 codifies that position as federal policy. Frequently asked questions about BOD 26-04 What is BOD 26-04? BOD 26-04 is a binding operational directive from CISA that requires all Federal Civilian Executive Branch (FCEB) agencies to prioritize vulnerability remediation based on a four-variable risk model. Unlike its predecessor BOD 22-01, which assigned flat remediation timelines to all vulnerabilities in the KEV catalog, BOD 26-04 evaluates each vulnerability against four criteria and assigns a remediation deadline based on the specific combination of risk factors present. The directive is mandatory for federal agencies but not for the private sector. However, CISA explicitly encourages private sector adoption, and the track record of BOD 22-01 suggests the framework will become a de facto standard across industries. BOD 22-01’s KEV catalog is already used by organizations worldwide as a prioritization signal, and BOD 26-04’s more sophisticated model will likely follow the same adoption curve. What are the four variables? BOD 26-04 determines remediation urgency using four binary variables: Publicly exposed - Is the vulnerable asset reachable from outside the agency network via a routable IP address? This is the only variable agencies must determine themselves. In the KEV - Is the CVE listed in CISA’s Known Exploited Vulnerabilities catalog? This confirms real-world exploitation. Automatable by adversary - Can an attacker automate all the steps necessary to exploit the vulnerability? This assesses weaponization maturity. Technical impact - Does exploitation give attackers total control of the affected system or only partial control? CISA publishes the answers to variables two, three, and four for every CVE through its Vulnrichment Program. Agencies must determine variable one (public exposure) using their own asset inventory and CISA’s Internet Exposure Reduction Guidance. What are the remediation timelines? Table 1 in Appendix A of the directive maps all 16 possible combinations of the four binary variables to specific remediation deadlines across five tiers: Three days with forensic triage - Required when a vulnerability is in the KEV and yields total system control (regardless of whether the asset is publicly exposed or the exploit is automatable). This is the most aggressive vulnerability management timeline in federal directive history. The forensic triage component requires agencies to assess whether their systems have already been compromised. Three days (without forensic triage) - Required for certain high-risk combinations, such as a publicly exposed asset with an automatable vulnerability yielding total control, even if the CVE is not yet in the KEV. 14 days - The standard accelerated timeline for most KEV-listed vulnerabilities and several high-risk non-KEV combinations. 60 days - Applied to lower-risk combinations, such as non-exposed assets with automatable but partial-control vulnerabilities. Fix on system upgrade - Applied when no risk criteria are met. This is the deferral tier, and it represents a significant operational relief for agencies: vulnerabilities that meet none of the four criteria can wait for the next scheduled upgrade cycle. Timelines are dynamic. If an agency removes a system from public internet exposure, the applicable timeline shifts to a longer window. Conversely, if CISA adds a vulnerability to the KEV catalog, the remediation timeline accelerates immediately. In an initial analysis at one large civilian agency, CISA found that only 1% of vulnerability instances fell into the three-day category, while over 60% qualified for deferral to the next system upgrade. The model is designed to focus resources, not overwhelm them. What changed from BOD 22-01? BOD 26-04 revokes and replaces BOD 22-01 entirely. The key differences are substantial: BOD 22-01 applied a flat remediation timeline to every vulnerability in the KEV catalog (14 days for CVEs assigned after 2021, six months for older CVEs). BOD 26-04 replaces this with a graduated model where KEV status is one of four variables, not the sole determinant of urgency. A KEV vulnerability on an internal system with partial control and no automation capability now receives 14 days, while the same KEV on a publicly exposed system with full automation and total control receives just three days with mandatory forensic triage. BOD 22-01 had no deferral mechanism. Every KEV required action. BOD 26-04 introduces the “fix on system upgrade” tier for vulnerabilities that meet none of the four risk criteria, allowing agencies to focus on the ones that matter most rather than chasing every vulnerability with equal urgency. BOD 22-01 had no forensic triage requirement. BOD 26-04 introduces mandatory forensic analysis for the highest-risk tier, recognizing that when a vulnerability is actively exploited and yields total system control, patching alone is insufficient: organizations need to determine whether they’ve been compromised. The underlying methodology also shifts. BOD 22-01 relied primarily on the KEV catalog and CVSS scoring. BOD 26-04 is informed by CISA’s Stakeholder-Specific Vulnerability Categorization (SSVC) system, which provides a more nuanced, risk-informed vulnerability analysis methodology. Why did CISA issue BOD 26-04 now? Two converging factors drove the directive. The first is the deteriorating effectiveness of traditional vulnerability management. Citing the 2026 Verizon Data Breach Investigations Report, CISA’s blog post accompanying the directive notes that only 26% of KEV-listed vulnerabilities were fully remediated by organizations in 2025, a decline from 38% the previous year. Meanwhile, the median time to fully resolve vulnerabilities rose to 43 days. In an environment where exploitation can occur within hours of disclosure, the remediation gap is widening. The second factor is artificial intelligence. CISA explicitly states that AI is accelerating both vulnerability discovery and weaponization, narrowing the window of time that exists between vulnerability disclosure and exploitation. The directive aligns with priorities in the recent AI Executive Order , Promoting Advanced Artificial Intelligence Innovation and Security . As AI-enabled tools make it easier for adversaries to identify, weaponize, and deploy exploits at scale, the traditional “patch everything eventually” approach becomes untenable. Defenders need a framework that tells them what to patch first, and BOD 26-04 provides the framework enabling them to prioritize on an accelerated timeframe. This is a challenge Tenable has been tracking closely. The intersection of an AI-enabled threat landscape with already-declining remediation effectiveness creates a compounding problem: adversaries are getting faster while defenders fall farther behind. BOD 26-04 is a necessary policy response to this environment. I don’t work for a federal agency. How does BOD 26-04 affect my organization? While BOD 26-04 is mandatory only for FCEB agencies, its influence extends well beyond the federal government. BOD 22-
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CISA's BOD 26-04 mandates federal agencies to prioritize vulnerability remediation based on a four-variable risk model: public exposure, presence in the Known Exploited Vulnerabilities (KEV) catalog, adversary automation capability, and technical impact severity. This model creates 16 risk tiers with corresponding remediation deadlines, from three days with forensic triage for the highest risk vulnerabilities to deferral for the lowest risk. The directive replaces BOD 22-01's flat remediation timelines and introduces forensic triage requirements for critical vulnerabilities. It addresses challenges posed by AI-accelerated vulnerability discovery and exploitation, aiming to focus resources on the most dangerous vulnerabilities. The directive is mandatory for federal civilian agencies but is expected to influence private sector practices. It consolidates prior federal vulnerability policies into a single, risk-weighted framework aligned with modern exposure management principles.
Potential Impact
The directive changes federal vulnerability management by enforcing accelerated patching for the most dangerous vulnerabilities, including mandatory forensic triage to detect potential compromises. It aims to reduce the window of exposure to critical vulnerabilities, especially those that are publicly exposed, automatable by adversaries, and yield total system control. This graduated approach helps agencies focus remediation efforts on vulnerabilities that pose the greatest risk, potentially reducing successful exploitations and improving overall cybersecurity posture. The policy also acknowledges the increasing speed of exploitation driven by AI, addressing the widening remediation gap observed in recent years.
Mitigation Recommendations
BOD 26-04 itself is a policy directive rather than a vulnerability with a patch. Federal agencies must implement the four-variable risk model to prioritize vulnerability remediation according to the directive's timelines. Agencies should maintain accurate asset inventories to determine public exposure status and follow CISA's Internet Exposure Reduction Guidance. For the highest-risk vulnerabilities, agencies must conduct forensic triage to assess potential compromises. Organizations outside the federal government are encouraged to adopt similar risk-based prioritization frameworks. There is no patch or fix to apply for this directive; rather, compliance involves operational changes in vulnerability management processes.
Technical Details
- Article Source
- {"url":"https://www.tenable.com/blog/cisa-bod-26-04-FAQ-vulnerability-remediation-impact","fetched":true,"fetchedAt":"2026-06-11T23:44:43.363Z","wordCount":4096}
Threat ID: 6a2b486b815e7002b844cc70
Added to database: 06/11/2026, 23:44:43 UTC
Last enriched: 07/08/2026, 15:20:22 UTC
Last updated: 07/31/2026, 12:12:19 UTC
Views: 432
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.