:

CISA ORDERS FEDERAL AGENCIES TO PATCH CRITICAL FLAWS IN 3 DAYS

SECURITY DESK2 MIN READ
THU, JUN 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, requiring Federal Civilian Executive Branch agencies to patch critical exploited vulnerabilities within three days.

CISA's new directive sets an aggressive timeline for addressing actively exploited security flaws across federal systems. Agencies must apply patches to critical vulnerabilities within 72 hours of notification, a significant reduction from standard patching windows. Binding Operational Directives carry legal force and mandate compliance from all FCEB agencies. The three-day requirement applies specifically to vulnerabilities that meet CISA's criteria for critical severity and evidence of active exploitation in the wild. The directive reflects growing urgency around federal cybersecurity posture. Agencies that fail to comply face potential escalation and reporting requirements to senior leadership. CISA will monitor compliance through existing federal security frameworks and vulnerability tracking systems. The 72-hour window acknowledges the operational reality of federal IT environments while emphasizing speed over traditional change management procedures. Agencies must balance rapid patching with system stability and continuity. CISA maintains a catalog of known exploited vulnerabilities, which serves as the primary reference for determining which flaws trigger the three-day requirement. The agency regularly updates this list based on threat intelligence and incident data. This directive joins CISA's earlier BOD 22-01, which required agencies to patch critical remote code execution and authentication bypass vulnerabilities within 15 days. The new 26-04 directive tightens that timeline for the most dangerous threats. Federal agencies must designate patch management coordinators and establish processes for rapid vulnerability assessment, testing, and deployment. IT teams will need to streamline change approval workflows to meet the compressed timeline. CISA encourages agencies to leverage automated patch management tools and maintain pre-positioned testing environments to accelerate deployment. The directive also permits temporary mitigations for systems requiring extended testing before patching.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

D-Link has alerted users of a maximum-severity zero-day vulnerability (CVE-2026-86296) affecting DIR-822A dual-band Wi-Fi routers. The flaw has no available patch and public exploit code is already circulating.

1H AGOSecurity Desk

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

9H AGOSecurity Desk

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

10H AGOSecurity Desk

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

12H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.