
Blog
Zafran Team
Zafran Announces Strategic Investment from Cisco Investments
July 22, 2026
CISA now requires federal agencies to remediate critical, actively exploited vulnerabilities within three days. Here is what BOD 26-04 changes, and why it matters for every security team, federal or not.

On June 10, 2026, CISA issued Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk." For federal civilian agencies, it rewrites how vulnerability remediation works. For everyone else, it confirms something security leaders have argued for years: in the age of AI-accelerated attacks, treating every CVE as equally urgent is a losing strategy.
Here is what the directive does, and how it lines up with the way Zafran already approaches exposure.
CISA is direct about the trigger. Attackers exploit unpatched vulnerabilities, and their growing use of AI shrinks the time defenders have between a patch being released and a working exploit being available. Programs designed for slower, human-speed workflows cannot keep pace when exploitation arrives in hours instead of weeks.
So CISA changed the model to focus effort where the risk is real.
The old approach leaned on CVSS base scores. By revoking the earlier BOD 19-02, CISA removed the requirement for federal agencies to use CVSS for prioritization at all. In its place sits a four-variable model drawn from the SSVC methodology. Every vulnerability is evaluated on four questions:
The combination of answers sets the remediation deadline.

The most urgent tier, three calendar days plus a forensic triage, is reserved for vulnerabilities that are already being exploited, grant total control, and are either internet-facing or automatable. At the other end, a vulnerability that is not exposed, not in the KEV, and not automatable can wait for the next scheduled system upgrade. Everything else lands on a 14-day or 60-day clock in between.
The design philosophy is deferral by intent: concentrate on the small set of vulnerabilities that can actually cause an incident, and stop burning cycles on the ones that cannot.
One detail rewards a closer read. The directive treats its timelines as dynamic. Remove a system from the internet, and the value of "Publicly Exposed" flips from Yes to No, which relaxes the required timeline. CISA calls this a valid mitigation. For the three-day tier, the directive accepts a mitigation action, rather than only a completed patch, as meeting the deadline.
That is a compensating control doing exactly what it should: cutting real risk now, while the patch follows on its own schedule. And it is how modern programs survive a three-day clock. Few teams can test and roll out a patch across a fleet in 72 hours. A reachability change pushed through a firewall, WAF, or endpoint control can happen in minutes.
The framework did not stay theoretical for long. Days after the directive took effect, CISA added CVE-2026-10520, a maximum-severity flaw in Ivanti Sentry, to the KEV catalog and set a three-day remediation deadline. The vulnerability is an OS command injection bug that lets a remote, unauthenticated attacker run code as root on publicly exposed instances.
Within days, the Shadowserver Foundation reported 19 exposed instances in its scans, two of them already backdoored, which is precisely the "assume compromise and verify" scenario the tier is built for.
The vendor guidance also shows the mitigation lever at work. Keeping the management interface off the public internet stops the instance from being internet-facing, which moves the asset out of the three-day box. The fix and the directive's own timeline mechanic are the same action.

BOD 26-04 binds federal civilian agencies. Its influence will not stop there.
CISA's last major directive, BOD 22-01, created the KEV catalog and became a de facto standard across the private sector, picked up by commercial security teams, auditors, and cyber insurers. BOD 26-04 is its successor, and the same gravity applies. Boards will ask whether your program aligns with it. Auditors will use it as a yardstick. The move away from CVSS-only scoring toward exploitability now carries the weight of a binding federal directive, which gives any security leader a strong reference point.
The rationale behind the directive applies universally. AI compressing the time to exploit hits a commercial bank or a manufacturer the same way it hits a federal agency. The threat does not check whether you are in scope.
SSVC (Stakeholder-Specific Vulnerability Categorization) is a decision-tree framework developed by Carnegie Mellon's CERT/CC with CISA that prioritizes vulnerabilities by running them through context-based decision points to produce a concrete action recommendation for each CVE. Zafran runs this exact model for you. Its SSVC engine computes a decision for every CVE finding using CISA's Deployer model and outputs one of four actions, each mapped to a BOD timeline:
Each decision is built from four points. Zafran determines whether an asset is internet-facing from your own integrated scanner, CSPM, and EDR data. Exploitation status (Active, PoC, or None), automatability, and technical impact (Total or Partial) come from continuously updated CVE intelligence. Pairing your environment with live exploit intelligence is what turns a generic CVE into a decision specific to your estate.
Two things make the result track real risk more closely than the directive's baseline. Where the BOD uses a binary in-the-KEV flag, Zafran uses the full three-level exploitation signal, so a public proof-of-concept is treated as more urgent than silence even before a vuln reaches the KEV. And Zafran layers in the context the four points leave out: runtime presence, business criticality, and which compensating controls already cover the asset.
The decision appears on the Investigate page next to every finding, with a tooltip that explains in plain language why the finding landed where it did and what its CISA timeline is. You can filter the entire findings list by decision, so one click on ACT surfaces everything due in three days, and ATTEND gives you the 14-day queue.

The directive's remediation-versus-mitigation distinction is built into the workflow as well. Every finding offers Mitigation Steps (compensating controls that cut risk now), Remediation Steps (the patch), and Request Exception (documented risk acceptance). Patches take weeks. Exploits take hours. A compensating control takes minutes.
BOD 26-04 is a clear marker of where vulnerability management is heading. Exploitability drives prioritization. Mitigation counts as action. Low-risk findings can wait. The Ivanti Sentry scramble is what that world looks like in practice, and more three-day clocks are coming. Zafran was built for this model, computing the SSVC decision for every finding and handing your team the mitigation path to hit the deadline, federal directive or not.
Traditional vulnerability management must change. So many are drowning in detections, and still lack insights. The time-to-exploit window sits at 5 days. Implementing a Continuous Threat Exposure Management (CTEM) program is the path forward. Moving from vulnerability management to CTEM doesn't have to be complicated. This guide outlines steps you can take to begin, continue, or refine your CTEM journey.
