Research

Three days: what the KEV Catalog shows about the new federal patching clock

We analyzed all 1,709 entries in CISA's Known Exploited Vulnerabilities Catalog. The federal remediation deadline for the highest-risk vulnerabilities has fallen from 181 days to three, and most of that drop happened on a single day in June 2026.

·

10 min

var(--variable-rpcX8dOAk)

Key findings

The median remediation window for a KEV entry has fallen from 181 days in 2021 to three days for entries added since June 2026.

The change is visible in the data on the day BOD 26-04 took effect. There is no transition period and no middle ground: every entry added since carries either a three-day or a fourteen-day deadline, nothing between.

A forensic triage requirement appeared on 1 July 2026 and now applies to 55 percent of entries added since the directive.

FedRAMP has aligned to the directive with a dated deadline. Its Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory on 7 December 2026.

Most organizations that track CISA’s Known Exploited Vulnerabilities Catalog treat it as a list. A CVE appears, it goes into the queue, someone patches it.

The catalog is also a record of how much time the federal government thinks you have. Every entry carries the date CISA added it and the date remediation is due, and the gap between those two dates is a policy position expressed as a number.

That number has changed dramatically, and most of the change happened on one day.

What we did

We pulled the complete catalog from cisagov/kev-data, CISA’s own GitHub mirror, published under CC0. The file analyzed is catalog version 2026.09.11, released 11 September 2026, containing 1,709 entries.

For each entry we computed the remediation window as dueDate minus dateAdded, in days, then grouped by the year and month the entry was added. Nothing here is modelled or estimated. It is subtraction on a published dataset, and anyone can reproduce it.

The window by year

Year added

Entries

Median window

2021

311

181 days

2022

555

21 days

2023

187

21 days

2024

186

21 days

2025

245

21 days

2026

225

14 days

The first drop is well known. BOD 22-01, issued in November 2021, set the two-week standard that held for four years.

The second drop is not, and the annual view understates it. Broken down by month, 2026 runs 21 days in January and February, 14 days from March through May, and three days from June onward.

3 days

median remediation window for KEV entries added since BOD 26-04 took effect, down from 21 days

75%

of the 92 entries added since the directive carry a three-day deadline

55%

of those entries also require forensic triage to establish whether the system is already compromised

102

entries in 2026 carry a window of three days or less, against eight across the four preceding years combined

Qwalora analysis of CISA Catalog of Known Exploited Vulnerabilities, version 2026.09.11, released 11 September 2026, 1,709 entries. Method described in this piece.

The directive

CISA issued Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, on 10 June 2026. It supersedes and revokes BOD 19-02 from 2019 and BOD 22-01 from November 2021.

The directive asks four questions of each vulnerability: is the affected asset publicly exposed, is the vulnerability known to be exploited, can exploitation be automated, and what technical impact does it give an attacker. A vulnerability that meets all four criteria must be remediated within three days.

CISA’s stated reason for the change is not compliance tidiness. The directive is shaped by the agency’s assessment that artificial intelligence is compressing the time between a vulnerability becoming known and it being weaponized.

The data lands exactly on the directive

Splitting the catalog at 10 June 2026 produces two populations that barely resemble each other.

The 1,617 entries added before that date have a median window of 21 days. The 92 entries added since have a median of three.

The distribution is the more striking part. Across those 92 entries there are exactly two values. Sixty-nine carry a three-day deadline. Twenty-three carry fourteen. Nothing else. No seven-day entries, no ten, no twenty-one.

That is what a rule looks like in data. The directive defines a risk tier, and CISA is sorting each entry into it or out of it on the day of publication.

The scale of the shift

Entries with a window of three days or less, by year:

2021

2022

2023

2024

2025

2026

0

0

0

1

7

102

Eight in the four years to the end of 2025. One hundred and two in the first nine months of 2026.

The forensic triage requirement

The catalog schema gained a field we had not seen before: forensicTriage, taking the value Yes or No.

Fifty-one entries carry Yes. Every one of them was added on or after 1 July 2026, and together they account for 55 percent of post-directive entries.

This is the part with the largest operational consequence and the least attention. A three-day patching deadline is a scheduling problem. A requirement to establish whether the system was already compromised before you patched it is an incident response problem, and it needs different people, different tooling, and evidence retention that patching alone does not produce.

What changed between the two directives

BOD 22-01, from 2021

BOD 26-04, from June 2026

Presence in the KEV Catalog sets the deadline

Presence in the KEV Catalog sets the deadline

Four risk criteria set the deadline: exposure, exploitation, automatability, impact

Two weeks for the large majority of entries

Two weeks for the large majority of entries

Three days for entries meeting all four criteria

A single population of due dates

A single population of due dates

Two tiers only, three days or fourteen, with nothing between

Remediate the vulnerability

Remediate the vulnerability

Remediate, and establish whether the system was already compromised

Timelines stable for four years

Timelines stable for four years

Timelines reassessed annually, with further reductions explicitly contemplated

What this means if you run federal systems

Three days is not a patch cycle. For most organizations, three days is shorter than the change advisory board meets. Agencies are directed to establish change management processes and continuity of operations plans that facilitate these timelines, which in practice means pre-authorizing emergency change for this class of vulnerability rather than routing it through normal governance.

Asset exposure has to be a known quantity, not a lookup. Three of the four criteria depend on knowing where the asset sits and what it can reach. An organization that cannot answer “is this internet-facing” in minutes cannot apply the directive at all, regardless of how fast it patches.

Forensic triage needs an owner before it is needed. Fifty-five percent of post-directive entries carry the requirement. If nobody has decided who performs triage, against what evidence, and how the finding is recorded, that decision gets made during the three-day window.

The timelines are expected to tighten. CISA commits to reassessing the remediation timelines once per fiscal year, and to running case study assessments to determine whether technological or adversarial advances warrant further reductions. Architecture built to exactly three days has no margin.

If you hold or want a FedRAMP authorization

FedRAMP has aligned to the directive publicly. Its Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory on 7 December 2026, explicitly to align with BOD 26-04.

That is a fixed date on the calendar, and it applies to cloud service providers rather than only to agencies. If your continuous monitoring process was built around a 30-day scan-and-report rhythm, it is now roughly eleven weeks from needing to be something else.

Secondary observations

Two patterns in the wider catalog are worth recording, though they are context rather than findings.

Vendor concentration has not moved much. Microsoft accounts for 388 of 1,709 entries across the catalog’s life, about 23 percent, and remains first in 2026 with 38 entries.

Ransomware association has fallen. The share of entries flagged as having known ransomware campaign use has roughly halved, from 27 percent of 2021 additions to 12 percent of 2026 additions. We would not read that as ransomware declining. knownRansomwareCampaignUse is Unknown for 1,349 of 1,709 entries, so the field records what CISA has established rather than what is true, and the denominator has grown.

Method, limits, and what this does not establish

Every figure above is arithmetic on a single published file, named and dated, and is reproducible by anyone who downloads it.

Three limits are worth stating.

The window we measure is the published deadline, not observed remediation. This piece says nothing about whether agencies actually meet these dates, which the catalog does not record.

The post-directive population is 92 entries over three months. The pattern is unambiguous, but it is early, and a single unusual month would move the medians.

The catalog is updated multiple times per week. Everything here reflects version 2026.09.11. Anyone acting on it should pull the current file rather than relying on ours.

Qwalora holds no partnership, reseller agreement, or commercial relationship with any vendor named in this piece. Vendor counts are descriptive of the catalog and are not an assessment of any vendor’s security posture. A vendor with many KEV entries may simply have large installed base and good disclosure practice.

Sources

  1. Cybersecurity and Infrastructure Security Agency. Catalog of Known Exploited Vulnerabilities. Version 2026.09.11, released 11 September 2026. Retrieved from the CISA data mirror (CC0). https://github.com/cisagov/kev-data

  2. Cybersecurity and Infrastructure Security Agency. BOD 26-04: Prioritizing Security Updates Based on Risk. Issued 10 June 2026. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk

  3. Cybersecurity and Infrastructure Security Agency. BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk. Read September 2026. https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk

  4. FedRAMP. FedRAMP Response to CISA BOD 26-04 (Prioritizing Security Updates Based on Risk). Public Notice 0014, June 2026. https://www.fedramp.gov/notices/0014/

  5. Cybersecurity and Infrastructure Security Agency. Known Exploited Vulnerabilities Catalog. Read September 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Tell us what you are deciding.