#BOD 26-04
10 stories taggedBOD 26-04.

CISA Gives Federal Agencies Three Days to Patch Two Zammad Flaws Being Exploited Now
Two critical bugs in the Zammad helpdesk platform can be chained for root-level takeover. CISA added both to the Known Exploited Vulnerabilities catalogue on 2 October 2026, with a patch deadline of 5 October.

CISA tells federal agencies: patch three Linux kernel bugs within days, attackers already using them
Three Linux kernel flaws are being exploited in the wild. Federal agencies have until 21 September to patch, and the most serious carries a 9.8 severity score.

CISA Is Scrapping Its Weekly Vulnerability Bulletin
The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

CISA Orders Federal Agencies to Patch Two Linux Kernel Flaws
The KEV catalog additions are the first Linux kernel entries to test Binding Operational Directive 26-04's risk-based patching regime.

CISA Warns of Active Attacks on Critical NetScaler Flaw
Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

CISA: Most Breaches Still Start With Old, Unpatched Bugs
A new review from the US cyber agency finds attackers rarely need clever tricks. They scan for known, exposed flaws that companies never got around to fixing.

CISA flags four actively exploited flaws in Microsoft, VMware and Apple products
The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin
A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.