CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage Order
Security / analysis
CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage Order
The October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.

CISA added five old vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue on October 8, 2026, and gave federal civilian agencies until October 11 to deal with all of them. Four of the five also carry a forensic triage requirement, which means agencies must check for compromise and not only apply a fix. Under the directive that governs the catalogue now, a three-day deadline is an instruction to investigate first.

The five entries
The KEV catalogue lists each entry with a due date of October 11 and ransomware use marked "Unknown". CISA does not say who is exploiting them, against whom, or why these particular bugs were added on this date.
| CVE | Product | Flaw | Forensic triage |
|---|---|---|---|
| CVE-2015-5477 | ISC BIND | Denial of service via TKEY queries | No |
| CVE-2015-3306 | ProFTPD | Arbitrary file read and write via site cpfr and site cpto | Yes |
| CVE-2016-3081 | Apache Struts | Command injection via method: prefix when Dynamic Method Invocation is enabled | Yes |
| CVE-2021-3199 | ONLYOFFICE Docs | Path traversal in an image upload parameter when JWT is used | Yes |
| CVE-2023-22894 | Strapi | Cleartext storage of sensitive data, reachable from the admin panel | Yes |
Two of these carry preconditions that limit who is at risk. The Struts bug needs Dynamic Method Invocation switched on. The Strapi entry says it can be chained with CVE-2023-22621 for remote code execution, and CISA marks the affected versions as possibly end-of-life, advising users to discontinue use or move to a supported version. The BIND flaw is the only one of the five with no triage order, and CISA describes it only as a denial-of-service flaw.
What the directive changed
The three-day clock and the triage flag come from BOD 26-04, issued on June 10, 2026. It revoked BOD 19-02, dated April 29, 2019, and BOD 22-01, dated November 3, 2021. The new text ties urgency to four facts: whether the asset is exposed to the internet, whether the flaw is in the catalogue, whether the exploit can be automated, and whether the attacker gains partial or total control.
The directive says the forensic triage tier requires remediation or mitigation within three days "to assess whether the system is compromised". The implementation guidance lays out six steps, from scoping in the first two hours to a triage report between 48 and 72 hours.
The guidance carries an instruction that sits awkwardly beside a three-day patch window. Step 3 says: "Collect all required evidence prior to this step as patching may jeopardize the availability of artifacts." An agency that patches a ProFTPD server on day one, before capturing memory, has met the deadline and may have destroyed what the triage was meant to examine. The guidance calls its own hour-by-hour timeline a recommended target and says "the specific timeline below is not required", but it makes no such allowance for the evidence order. It also says CISA "does not issue waivers or exceptions".
How the catalogue looks since June 10
A count of the catalogue shows how much of it now arrives with a triage order.
- 3 days, forensic triage78 entries
- 3 days, no triage21 entries
- 14 days, no triage23 entries
Source: CISA Known Exploited Vulnerabilities catalogue JSON, accessed 2026-10-10; counts by dateAdded, dueDate and forensicTriage fields
Every 14-day entry in that period has no triage order. The longer window went to flaws such as the two Chromium V8 bugs added in early September and, on September 29, Apple's CoreGraphics zero-day, CVE-2026-86950. The two Zammad zero-days added on October 2 are on the three-day list with a triage order. Entries the directive treats as exposed, automatable and fully controlling get three days and an investigation.
The old-bug batch is not unusual. Thirteen of the 122 entries carry CVE numbers from 2015 to 2023, including a batch on August 26, so a CVE from 2015 in the catalogue now means exploitation observed in 2026, not a stale record. August 26 added five at once, CVE-2021-23758, CVE-2015-3246, CVE-2015-5287, CVE-2022-0995 and CVE-2019-1068, and CVE-2023-49105 followed on August 27. New bugs sit in the same queue: the Citrix NetScaler zero-day entry added on October 4 also has a three-day window.
What it means for operators
The directive applies to federal civilian agencies, and contractors are exempt unless a procurement contract says otherwise. Private operators are not bound by it, but the catalogue is public, and its triage flag is a free signal about which entries CISA expects to be a compromise rather than a hygiene lapse. An organisation running ProFTPD, Strapi, ONLYOFFICE Docs or a Struts application with Dynamic Method Invocation on should capture volatile data before patching and then search for prior access.
The FedRAMP vulnerability-reporting requirement in the implementation guidance becomes mandatory on December 7, 2026. CISA says it reassesses the deadline table once per fiscal year, so the three-day tier the five October 8 entries sit in is not fixed. Until that review, the date to hold agencies to is October 11, and the evidence order in Step 3 is the part of the guidance most likely to be skipped in a rush to meet it.
Sources
More in Security
- 01Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 02Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 03Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.
- 04Citrix's Third NetScaler Zero-Day in Seven Days Crashes Appliances Already PatchedCVE-2026-88779 hits SAML-configured NetScaler boxes that had just taken the Sept. 27 fixes, and attackers were already trying to drop a payload through it.