The short answer
Stop treating severity as the deadline
CISA’s new three-day tier does not apply to every vulnerability labeled Critical. It applies to the most dangerous combinations of real-world exploitation, public exposure, automated attack potential, and system impact.
Likewise, CISA no longer provides a simple “High gets this many days, Medium gets that many” schedule in its current federal directive. A Medium-rated vulnerability that attackers are exploiting may outrank a theoretical Critical vulnerability that is isolated and difficult to weaponize.
On June 10, 2026, the Cybersecurity and Infrastructure Security Agency issued Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk. The directive replaces the earlier federal model that emphasized broad CVSS severity and fixed Known Exploited Vulnerabilities deadlines.
The philosophy is simple: patch the vulnerabilities most likely to become damaging incidents first. CISA describes the approach as “patch smarter, not harder.”
The new clocks are 3, 14, and 60 days
BOD 26-04 produces four operational outcomes. All stated deadlines are calendar days.
3
days
Highest-risk combinations. Some also require forensic triage to determine whether the affected system was already compromised.
14
days
Elevated-risk vulnerabilities, including many Known Exploited Vulnerabilities and dangerous publicly exposed flaws.
60
days
Lower-risk findings that still have meaningful exposure or automation characteristics.
Upgrade
scheduled cycle
The lowest-risk combinations may wait until the asset’s next scheduled major upgrade or rebuild.
The deadline starts when CISA adds the vulnerability to the Known Exploited Vulnerabilities catalog or the agency identifies it on an asset, as applicable. The calculation can change when the facts change—for example, when a system becomes publicly exposed or CISA adds the vulnerability to the catalog.
Four questions replace the Critical/High shorthand
The new model asks four binary questions about each vulnerability instance:
-
1
Is the asset publicly exposed?
An internet-reachable vulnerable service gives an attacker a direct path and shortens the defensive window.
-
2
Is the vulnerability in CISA’s KEV catalog?
A Known Exploited Vulnerability has evidence of exploitation in the wild. That is stronger evidence of urgency than a theoretical severity score alone.
-
3
Can an adversary automate exploitation?
Automation lets attackers scan and compromise vulnerable systems at scale, accelerating exposure from days to hours.
-
4
Is the technical impact total or partial?
Total control carries more urgency than a limited effect. CISA publishes decision data through its Vulnrichment project.
The full 16-row decision matrix is also available in the CERT/CC implementation of CISA’s response model.
Three days is the top tier—not a synonym for Critical
A vulnerability can reach the three-day tier through several paths. Examples include:
- A publicly exposed KEV that can be exploited automatically.
- A publicly exposed, automatable vulnerability that gives an attacker total control—even if it is not yet in KEV.
- A KEV that is automatable and grants total control, even when the vulnerable asset is not publicly exposed.
- A KEV that grants total control on a publicly exposed system.
A practical private-sector policy
BOD 26-04 is binding on Federal Civilian Executive Branch agencies. It is not a universal legal deadline for every private company. Still, it provides a useful operating benchmark because the risk factors apply everywhere.
Organizations that need simple service-level labels can translate the CISA outcomes into internal language:
Important: This translation is an internal policy suggestion, not CISA’s official Critical/High/Medium/Low mapping. The four-factor decision should always override the label when it produces a faster deadline.
A defensible program should also document compensating controls and exceptions. Removing public exposure, isolating a service, or disabling vulnerable functionality can reduce immediate risk, but the organization should still record ownership, the final remediation action, and the evidence used to close the finding.
The operational takeaway
The headline is not “all Critical vulnerabilities now have three days.” The better headline is that CISA has moved from severity-driven queues to evidence-driven response.
That means vulnerability teams need more than scanner scores. They need accurate asset inventories, internet-exposure data, KEV monitoring, exploitability intelligence, clear ownership, and the ability to launch forensic triage quickly. Without that context, a three-day policy becomes an arbitrary race. With it, the deadline focuses attention on the small set of vulnerabilities most likely to become incidents.
Primary and technical sources