BLUF;

  • CISA’s new guidance shifts organizations away from patching every vulnerability immediately and toward focusing first on those that pose the greatest real-world risk.
  • Focus on the vulnerabilities that matter most. The highest priority vulnerabilities are those that are internet-facing, easily exploitable, capable of giving attackers significant control, and are already being actively exploited.
  • BOD 26-04 introduces a risk-based patching framework that helps organizations prioritize the most dangerous vulnerabilities first, enabling faster remediation of critical threats while allowing lower-risk issues to be addressed on longer timelines.

Artificial intelligence is assisting both researchers and adversaries in identifying flaws in software, vastly increasing the pace at which new vulnerabilities are discovered. Defenders are already struggling to keep up. Per Verizon’s 2026 Data Breach Investigations Report, only 26% of vulnerabilities on CISA’s Known Exploited Vulnerabilities (KEV) Catalog were fully remediated by organizations in 2025, a drop from the previous year’s 38%. The median time for full resolution rose to 43 days.

Defenders need greater clarity and speed to patch systems in today’s threat landscape. Experts believe patch prioritization should be updated: patch smarter, not harder.

CISA’s BOD 26-04 for Patching Prioritization

CISA’s Binding Operational Directive 26-04 (BOD 26-04), “Prioritizing Security Updates Based on Risk” presents a new framework for patching prioritization and incident management best practices. Under this directive, agencies are empowered to defer lower priority vulnerabilities and focus efforts on the areas of highest risk.

From CISA’s vantage point as the Nation’s cyber defense agency, it has become clear that the greatest risk stems from vulnerabilities displaying four characteristics:

  • Public exposure
  • Ability for an attacker to fully automate exploitation
  • Whether exploitation gives an attacker full control of a system
  • Evidence of real-world exploitation (i.e., a KEV)

Using the criteria above, only the highest risk vulnerabilities must be patched within three days, while vulnerabilities presenting less risk may be remediated over longer timelines, even possibly deferred until the next system upgrade.

Some may notice that this patching framework mostly prioritizes vulnerabilities sitting at the network’s edge, which may seem to overlook the network’s core. However, in practice, CISA does not observe threat actors primarily compromising core networks through product vulnerabilities. Instead, threat actors often use exploitable configurations and valid credentials. This is a technique known as living off the land (LOTL). LOTL is better addressed through other means, such as hardening system configurations, network segmentation, and phishing-resistant multi-factor authentication enforcement.

This new approach to vulnerability prioritization has already had proven success in focusing and strengthening Federal government vulnerability management.

In an initial analysis at one large civilian agency, only 1% of vulnerability instances fall into the three-day category, with over 60% of the vulnerability instances deferred to the next system upgrade. This more aggressive tiering of vulnerabilities ensures that the most critical vulnerabilities are addressed first, and more quickly.

BOD 26-04 is a major stride toward addressing the cybersecurity risks posed by AI advancements as the cybersecurity community strives to automate and scale vulnerability management and bolster software engineering security practices to counter the evolving threat landscape.


SecureStrux

SecureStrux

As a cybersecurity firm with deep roots in the Department of War (DoW) cybersecurity community, we provide specialized services in the areas of compliance, vulnerability management, cybersecurity strategies, and engineering solutions. Since 2013, we’ve partnered with hundreds of organizations within and outside the DoW to understand and proactively manage their risk. Our strength within the DoW has allowed us to easily translate best practices to our clients in other industries including Energy, Manufacturing, Architecture, Education, and Aerospace.

The latest in Cybersecurity

Enter your email to get the latest news, updates,
and content on cybersecurity.

"*" indicates required fields

How Did You Hear About SecureStrux?