CISA Sets 72-Hour Deadline for Federal Agencies to Patch Software Vulnerabilities
CISA issued bulletin BOD 26-04, establishing a strict 72-hour deadline for federal agencies to remediate known software vulnerabilities. The directive updates definitions, timelines, and criteria for vulnerability management practices across the government.
The timeline aligns with the White House’s Gold Eagle initiative, which centralizes vulnerability coordination through a national clearinghouse. Federal security teams have noted that current triage tools operate too slowly to meet the new window. Cognition AI will host a webinar on Aug. 7 to demonstrate how its Devin Security Swarm can automate patch deployment to comply with the directive.
From the sources (2 posts)
@cisagovVulnerability management practices must keep pace with the ever-evolving threat environment. We issued BOD 26-04 to provide clear definitions, timelines, and criteria to enhance vulnerability remediation. See how your org. can implement the
@justinherman72 hours. That's how long federal agencies now have to remediate a vulnerability under @CISAgov's BOD 26-04. And now with the @WhiteHouse's new Gold Eagle initiative centralizing vulnerability coordination through a national clearinghouse,