CISA's New Patching Directive Drops CVSS as the North Star

BOD 26-04 introduces a four-factor framework that prioritizes internet exposure, active exploitation, and attacker automation over raw severity scores — and gives agencies three days to act on the worst cases.

ThreatVectr Newsdesk· 3 min read
CISA's New Patching Directive Drops CVSS as the North Star
Share

Federal vulnerability management just changed its core logic.

CISA issued Binding Operational Directive 26-04 this week, formally replacing severity-score-driven patching timelines with a risk-based framework built around four criteria: whether a vulnerable system faces the public internet, whether the vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, whether exploitation can be automated, and how much control a successful attacker would gain. Vulnerabilities hitting three or more of those conditions must be remediated within three days.

The backdrop is grim. The Verizon 2026 Data Breach Investigations Report found organizations fully remediated just 26% of actively exploited vulnerabilities last year — down from 38% the year prior. Median time-to-patch for known dangerous flaws sat at 43 days. Attackers, meanwhile, have compressed their exploitation timelines to hours in some cases.

"Defenders cannot afford to take weeks to patch systems that can be autonomously exploited en masse," said Chris Butera, acting executive assistant director for cybersecurity at CISA, during a media briefing announcing the directive.

The shift away from CVSS has drawn praise from practitioners who have argued for years that severity scores are poor predictors of actual exploitation. "Patching every CVSS High or Critical is mathematically impossible," said Jerry Gamblin, a member of FIRST's EPSS special interest group and founder of RogoLabs. "By formalizing the use of the KEV catalog alongside advanced predictive data like EPSS, CISA is helping drive the industry toward practical, risk-based operational maturity."

CISA's own analysis of one federal civilian agency found roughly 1% of vulnerability instances required the three-day response window, while more than 60% could be deferred to the next scheduled system update. The agency frames this as the directive's core value: focus scarce remediation resources on the small subset of flaws most likely to result in compromise.

Remediation timelines are also dynamic under the new framework. A vulnerability's required response window can tighten as circumstances change — say, a proof-of-concept drops publicly or KEV adds the CVE.

Not everyone sees it as a complete solution. Sasha Romanosky, a senior cybersecurity policy researcher at RAND, welcomed the move away from pure severity scoring but noted the directive's treatment of impact is narrow, focused mainly on whether exploitation grants an attacker partial or full system control. Integrity impacts — data manipulation, denial-of-access scenarios — receive less explicit treatment.

The KEV catalog itself draws scrutiny. Michael Roytman, co-founder and CTO of Empirical Security, called the directive a milestone but flagged a structural problem: "KEV lists are binary and retroactive. When AI compresses the gap between patch and exploit to hours, waiting for the KEV entry means you find out you were wrong from the incident report."

That tension — between a catalog that captures confirmed exploitation and an AI-accelerated threat environment that moves faster than any catalog can — may be the directive's sharpest unresolved edge. Federal vulnerability management has historically foreshadowed commercial practice. Security teams outside government would do well to read BOD 26-04 as a preview.

© 2026 Threat Vectr