:

CISA ORDERS FEDERAL AGENCIES TO PATCH CRITICAL FLAWS IN 3 DAYS

SECURITY DESK2 MIN READ
THU, JUN 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, requiring Federal Civilian Executive Branch agencies to patch critical exploited vulnerabilities within three days.

CISA's new directive sets an aggressive timeline for addressing actively exploited security flaws across federal systems. Agencies must apply patches to critical vulnerabilities within 72 hours of notification, a significant reduction from standard patching windows. Binding Operational Directives carry legal force and mandate compliance from all FCEB agencies. The three-day requirement applies specifically to vulnerabilities that meet CISA's criteria for critical severity and evidence of active exploitation in the wild. The directive reflects growing urgency around federal cybersecurity posture. Agencies that fail to comply face potential escalation and reporting requirements to senior leadership. CISA will monitor compliance through existing federal security frameworks and vulnerability tracking systems. The 72-hour window acknowledges the operational reality of federal IT environments while emphasizing speed over traditional change management procedures. Agencies must balance rapid patching with system stability and continuity. CISA maintains a catalog of known exploited vulnerabilities, which serves as the primary reference for determining which flaws trigger the three-day requirement. The agency regularly updates this list based on threat intelligence and incident data. This directive joins CISA's earlier BOD 22-01, which required agencies to patch critical remote code execution and authentication bypass vulnerabilities within 15 days. The new 26-04 directive tightens that timeline for the most dangerous threats. Federal agencies must designate patch management coordinators and establish processes for rapid vulnerability assessment, testing, and deployment. IT teams will need to streamline change approval workflows to meet the compressed timeline. CISA encourages agencies to leverage automated patch management tools and maintain pre-positioned testing environments to accelerate deployment. The directive also permits temporary mitigations for systems requiring extended testing before patching.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days.

3H AGOSecurity Desk

The Department of Homeland Security is attempting to obtain Signal group chat messages from plaintiffs in a free-speech lawsuit against the agency. The move has raised concerns about using legal discovery to surveil encrypted communications.

9H AGOIndustry Desk

Maksim Silnikau, creator of the Ransom Cartel ransomware operation, received a 16-year prison sentence for orchestrating attacks against at least 18 companies worldwide.

9H AGOSecurity Desk

Atlassian's Rovo AI assistant can exfiltrate sensitive data despite organizational security controls. The vulnerability allows the tool to extract and transmit protected information beyond intended boundaries.

11H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.