logo

CISA to require federal agencies to patch some cyber vulnerabilities within 3 days

ID: 66b8aa47-e65f-5d64-bbaf-5fe0a10a79d7

STIX ID: report--66b8aa47-e65f-5d64-bbaf-5fe0a10a79d7

Feed Name: The Record from Recorded Future News

Date Published: 2026-06-10

Date Updated: 2026-06-11

...
...

CISA issued a binding operational directive requiring federal civilian agencies to remediate certain vulnerabilities within 72 hours when they meet three of four criteria (internet-exposed, listed in the Known Exploited Vulnerabilities catalog, automatable exploit, and degree of adversary control); agencies have 180 days to adopt the timeframe, CISA will assist with triage/forensics, and the agency encourages state, local, tribal, and critical infrastructure operators to adopt similar prioritization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.