CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

CISA has told federal civilian agencies they have three days to patch an actively exploited flaw in Ivanti Sentry, the first enforcement action under a newly issued Binding Operational Directive, BOD 26-04.
The directive compresses the patch window for known-exploited bugs well below the 15- and 21-day timelines agencies grew used to under BOD 22-01. Three days. That is the new floor when CISA designates something as urgent.
Ivanti Sentry — formerly MobileIron Sentry — sits in front of mobile device management deployments, brokering ActiveSync and other backend traffic. It is, in IAM terms, a gateway that often holds credentials, certificates, and session material for an entire mobile fleet. Compromising it is rarely a single-user problem.
The flaw CISA flagged is being used in the wild against unpatched systems exposed to the internet. Ivanti has published a fix and configuration guidance in its security advisory portal, and administrators should treat any internet-reachable Sentry instance as suspect until patched and reviewed.
A quick note on what MFA does and does not do here. Sentry brokers authentication for downstream services; if the box itself is owned, the attacker is operating below the layer where your conditional access policies live. Phishing-resistant MFA on user accounts is great. It does not save you when the authenticator-adjacent infrastructure is the thing being exploited.
The shift to a 72-hour SLA is a meaningful one for federal IT shops. Under the old regime, teams could batch KEV-listed CVEs into a normal change window. BOD 26-04 essentially eliminates that comfort for a subset of bugs CISA deems most dangerous, putting them closer to the emergency-directive cadence previously reserved for things like the SolarWinds and MOVEit incidents.
For identity teams specifically, three actions are worth doing now even if you are not a federal agency:
- Inventory every Sentry, Connect Secure, and Policy Secure appliance, including any forgotten lab instances. Internet exposure is the aggravating factor.
- Rotate any service-account credentials, API keys, and certificates the appliance touched. Assume session tokens and cached secrets are burned.
CISA's Known Exploited Vulnerabilities catalog is the authoritative list of what the directive covers, and the agency has indicated the new three-day clock applies to entries it explicitly tags under BOD 26-04 rather than every KEV entry retroactively.
Ivanti edge appliances have been a recurring entry point for state-aligned intrusions over the past two years. Treating them as crown-jewel infrastructure — patched fast, monitored hard, isolated from the rest of the identity plane — is the only posture that makes sense at this point.
The directive is binding on FCEB agencies. Everyone else should read it as strongly worded advice.



