:

CISA ORDERS FEDERAL AGENCIES TO PATCH CRITICAL FLAWS IN 3 DAYS

SECURITY DESK2 MIN READ
THU, JUN 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, requiring Federal Civilian Executive Branch agencies to patch critical exploited vulnerabilities within three days.

CISA's new directive sets an aggressive timeline for addressing actively exploited security flaws across federal systems. Agencies must apply patches to critical vulnerabilities within 72 hours of notification, a significant reduction from standard patching windows. Binding Operational Directives carry legal force and mandate compliance from all FCEB agencies. The three-day requirement applies specifically to vulnerabilities that meet CISA's criteria for critical severity and evidence of active exploitation in the wild. The directive reflects growing urgency around federal cybersecurity posture. Agencies that fail to comply face potential escalation and reporting requirements to senior leadership. CISA will monitor compliance through existing federal security frameworks and vulnerability tracking systems. The 72-hour window acknowledges the operational reality of federal IT environments while emphasizing speed over traditional change management procedures. Agencies must balance rapid patching with system stability and continuity. CISA maintains a catalog of known exploited vulnerabilities, which serves as the primary reference for determining which flaws trigger the three-day requirement. The agency regularly updates this list based on threat intelligence and incident data. This directive joins CISA's earlier BOD 22-01, which required agencies to patch critical remote code execution and authentication bypass vulnerabilities within 15 days. The new 26-04 directive tightens that timeline for the most dangerous threats. Federal agencies must designate patch management coordinators and establish processes for rapid vulnerability assessment, testing, and deployment. IT teams will need to streamline change approval workflows to meet the compressed timeline. CISA encourages agencies to leverage automated patch management tools and maintain pre-positioned testing environments to accelerate deployment. The directive also permits temporary mitigations for systems requiring extended testing before patching.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

2H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

4H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

9H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

12H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.