CISA Has Set a Three-Day Deadline on All 25 Exploited Flaws Since September 12, Against 21 Days in January
Security / analysis
CISA Has Set a Three-Day Deadline on All 25 Exploited Flaws Since September 12, Against 21 Days in January
The catalog file shows the tight deadline spreading through 2026, and the newest entries include products with no fixed build to install.
Every one of the 25 vulnerabilities CISA added to its Known Exploited Vulnerabilities catalog between September 12 and October 4 carries a three-day federal remediation deadline. In January, 15 of the 17 additions carried 21 days.
That shift is visible in the catalog file itself (version 2026.10.04, released October 4), which holds 1,734 entries, 250 of them added in 2026. It is a bigger change than any single advisory this month, and it is arriving on products whose vendors cannot always ship a patch inside the window.
What the catalog shows, month by month
Counting the days between dateAdded and dueDate for every 2026 entry gives this picture. The three entries not shown (two with 2-day deadlines in February, one with 5 days in May) are included in the month totals used for the percentages.
| Month added | 3-day | 14-day | 21-day |
|---|---|---|---|
| January | 2 | 0 | 15 |
| February | 4 | 0 | 22 |
| March | 5 | 14 | 7 |
| April | 8 | 23 | 0 |
| May | 7 | 13 | 0 |
| June | 17 | 6 | 0 |
| July | 22 | 4 | 0 |
| August | 21 | 10 | 0 |
| September | 35 | 8 | 0 |
The last 21-day entry went in on March 5, and the last 14-day entry on September 11. Since then, nothing. WordPress CVE-2026-87902, added September 25, got three days, as we reported, and so did every entry added after it, from Citrix NetScaler on September 27 to Apple CoreGraphics on September 29 and Cisco SD-WAN Manager on September 30. The 14-day entries still being added in September were JFrog Artifactory (CVE-2026-42016 and CVE-2026-42018), two Chromium V8 bugs, two Windows bugs, BerriAI LiteLLM (CVE-2026-59822) and Starlette (CVE-2026-48710).
- January12 %
- March19 %
- May33 %
- June74 %
- July85 %
- September81 %
Source: CISA Known Exploited Vulnerabilities catalog, version 2026.10.04, accessed 2026-10-07; shares computed from dateAdded and dueDate
Where the directive comes in
The June 10 date matters. CISA issued Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk," that day. Its page lists a 3-day tier with forensic triage for certain high-risk cases, a 14-day tier, and other periods from 30 days to "fix on system upgrade." It revokes BOD 19-02 from 2019 and BOD 22-01 from 2021.
BleepingComputer's coverage says the criteria are public exposure, KEV listing, whether exploitation can be automated at scale, and whether the attacker gains full or partial control. Agencies have 60 days to update policies and 180 days to meet the timelines in full. The two accounts word the 14-day tier differently: CISA's page ties it to known exploited flaws on publicly exposed assets, while BleepingComputer describes limited exploitation potential or partial control.
The catalog shows the three-day tier was in use before the directive. The first 3-day entry appeared on January 27. What changed in June is the share: 17 of 23 additions in June, against 7 of 21 in May. The data cannot say whether the directive caused that, because the catalog does not record which criterion applied to each entry.
When the deadline outruns the patch
A three-day clock is workable when a fixed build exists. The last five days of September and the first four of October show it is not always so.
CISA gave Citrix's CVE-2026-88779 a three-day window even though, as we reported, the September 27 NetScaler fix does not cover it. FortiMail's CVE-2026-104286 went in on October 1 with an October 4 due date while Fortinet's fixed builds 7.4.9, 7.6.7 and 8.0.2 were still unreleased. Zammad's CVE-2026-102490 went in October 2, due October 5, and Sysdig reported no patch as of October 5.
The catalog's required action covers this. For the Cisco SD-WAN entry it reads: apply mitigations "in accordance with vendor instructions," and "discontinue use of the product if mitigations are unavailable." For appliances without a patch, the deadline becomes a deadline to disconnect or isolate.
| Entry | Added | Due | Fixed build at disclosure |
|---|---|---|---|
| Citrix NetScaler CVE-2026-88779 | October 4 | October 7 | September 27 fix does not cover it |
| Zammad CVE-2026-102490 | October 2 | October 5 | None, per Sysdig |
| Fortinet FortiMail CVE-2026-104286 | October 1 | October 4 | None; 7.4.9, 7.6.7, 8.0.2 pending |
| Cisco SD-WAN Manager CVE-2026-76504 | September 30 | October 3 | Fixed builds on six trains |
What it does not show
The catalog marks ransomware use as "Unknown" for all 12 of the most recent entries, and 27 of the 250 entries added in 2026 as "Known". Forensic triage is flagged on 75 of the 250. The file says nothing about how many agencies met each date.
The deadline binds only federal civilian agencies. Everyone else uses the catalog as a priority list, and the mix above means a listing now tells them an exploit exists and a fix may not. The next test is the Citrix entry, due October 7, which is today.
Sources
More in Security
- 01Cling Botnet Hides Commands in the STUN Transaction ID and Spreads Through Realtek Flaw CVE-2021-35394Nozomi Networks says the malware sends traffic that resembles ordinary Google STUN replies, so defenders have to hunt for all-zero transaction IDs instead of blocking an address.
- 02Apple Fixes CoreGraphics Flaw CVE-2026-86950 in iOS 26.7.1 After Meta Reports Targeted AttacksApple's entry says a crafted file can run code and that exploitation may have hit specific people on iOS versions before iOS 27, but it names no victims and no attacker.
- 03NetScaler SAML Zero-Day CVE-2026-88779 Was Exploited Days After Two Others, and CISA's Deadline Is TodayCitrix rates the flaw 8.7 and calls it a denial of service, but a researcher's honeypot ran a downloaded binary, and appliances patched for last week's bugs need a second upgrade.
- 04Cloudflare's Open-Source Audit Skill Is at 25,900 Stars, but Its Own Post Shows 20,799 Candidates Became 7,245 Actionable FindingsThe repository trending on GitHub is the 450-line starting point. The funnel numbers in Cloudflare's June write-up describe a different system that has not been released.