CISA orders federal agencies to patch top-risk exploited flaws within 72 hours
Binding Operational Directive 26-04 sets a three-day deadline for vulnerabilities meeting all four risk criteria—KEV-listed, internet-exposed, exploit-automatable, and granting full system control—citing AI-enabled attackers shrinking the time to exploit.
The US Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04 on June 10, ordering federal civilian agencies to fix the highest-risk, actively exploited vulnerabilities within 72 hours.
The directive, titled "Prioritizing Security Updates Based on Risk," replaces two earlier patching mandates and reflects a view that attackers now move faster than older timelines assumed. It applies to Federal Civilian Executive Branch agencies, not the private sector.
Under the new directive, agencies must remediate within three calendar days any vulnerability that combines four risk characteristics: it appears on CISA's Known Exploited Vulnerabilities catalog; the affected asset is exposed to the internet; the exploit can be automated; and successful exploitation grants full system control. Where full system takeover is possible, agencies must check for prior compromise before patching. Less urgent high-risk flaws that cannot be exploited automatically get longer timelines.
CISA executives framed the driver as AI-enabled threat actors narrowing the window between disclosure and exploitation; the directive itself states that adversaries' "use of AI may further narrow the time defenders have to react." Chris Butera, CISA's acting executive assistant director for cybersecurity, and senior technical advisor Jonathan Spring urged agencies to "patch smarter, not harder." Nick Andersen, acting CISA director, said the rule lets agencies "focus their efforts on the areas of highest risk and defer patching lower priority vulnerabilities."
The rule is not immediately enforceable. Agencies have phased deadlines — 60 days to update policies and 180 days for broader remediation and asset-tagging requirements — with full enforceability beginning December 7, 2026 in a third phase. Senator Mark Warner (D-VA) introduced companion legislation the same week, and CISA urged state, local, tribal, and critical-infrastructure operators to adopt similar frameworks.
The 72-hour standard is among the most aggressive federal patching requirements to date, and its real test will be whether agencies running legacy systems can meet a three-day clock once enforcement begins in December.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
