• News/
  • bleepingcomputer-20260611124644

CISA tells govt agencies to patch critical exploited flaws in 3 days

BleepingComputer
·
Bill Toulas
·
Published Jun 11, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) agencies. The directive aims to reduce the threat of cyberattacks targeting the public sector by requiring agencies to remediate high-risk vulnerabilities within accelerated timeframes, in some cases as little as three days. CISA says that BOD 26-04 “supersedes and revokes” the older BOD 19-02 and BOD 22-01, introduced in 2019 and 2021, respectively. The agency says that prioritizing patching is based on four key considerations: Depending on these factors, agencies get deadlines for addressing security vulnerabilities, the shortest period being three days. For less urgent situations where automated exploitation is not possible or when it only provides partial control, the timeframe is set to two weeks. The directive applies specifically to U.S. Federal Civilian Executive Branch (FCEB) agencies and the information systems they operate. This includes government agencies and departments, but does not apply to certain military systems operated by the U.S. Department of War, private companies, Intelligence Community systems, and contractors. Like previous directives, the framework is expected to influence the broader cybersecurity industry and provide a broader patching priority signal. The directive applies to all on-premise federal systems, third-party hosted systems, and FedRAMP/non...

Read full article

Affected Software

1 affected component
Ivanti EPMM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's new Binding Operational Directive that mandates urgent security updates for government agencies.

2

What security implications are discussed in the article?

The article highlights the urgency of patching critical exploited vulnerabilities to prevent cyberattacks on public sector entities.

3

What software is specifically mentioned as affected by the directive?

The affected software mentioned in the article is Ivanti EPMM (Ivanti).

4

What is the deadline for agencies to implement the required patches?

Agencies are required to patch the critical vulnerabilities within three days of the directive.

5

What type of vulnerabilities are emphasized in the article?

The article emphasizes zero-day vulnerabilities that are actively exploited in cyberattacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203