BOD 26-04 Makes Exploitability the Priority Signal: Scanners Can’t Measure It
CISA's Binding Operational Directive 26-04, issued June 10, 2026, replaces the KEV directive with a four-variable risk model: asset exposure, KEV status, exploit automation, and technical impact. CISA publishes three of the four answers generically per CVE. The two that decide whether prioritization is defensible (real exposure and real impact in your environment) can only be proven by testing the asset the way an adversary would. Continuous, human-validated pentesting is built to produce that evidence.
Key Takeaways
- BOD 26-04, issued June 10, 2026, revokes and replaces BOD 22-01 (KEV) and BOD 19-02 (Internet-facing System), consolidating seven years of federal vulnerability remediation policy into one risk-weighted framework.
- Sixteen combinations of four binary risk variables map to five remediation tiers, from three days with mandatory forensic triage down to fix-on-next-upgrade.
- Asset exposure is the only variable agencies must determine themselves, and a wrong "not exposed" answer silently defangs an urgent 3-day remediation requirement into a 60-day exposure window.
- CVSS scores appear nowhere in the model. Evidence of exploitation, exposure of the truth, and demonstrated impact now set the deadlines.
- CISA's Acting Director urged all partners, not just federal agencies, to adopt the same practices, and the KEV catalog's adoption curve shows where this framework goes next.
Why BOD 26-04 Changes the Vulnerability Management Equation
On June 10, 2026, CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk”, and quietly ended the era of one-size-fits-all patching. In place of flat KEV deadlines, the directive asks four questions about every vulnerability on every asset and assigns a remediation deadline based on the answers. Federal civilian agencies must update policies immediately, update remediation processes within 60 days, and operate on the new timelines within 180 days.
CISA was explicit about why now. Artificial intelligence is compressing the window between vulnerability disclosure and weaponization, and the 2026 Verizon DBIR data CISA cited shows the gap widening in the wrong direction: only 26% of KEV-listed vulnerabilities were fully remediated in 2025, down from 38% the year before, while median time to resolve climbed to 43 days. Adversaries are getting faster. Defenders are falling behind. The outdated, rigid timelines were not just simplistic—they were failing to keep pace with modern threats.
What BOD 26-04 Requires
Remediation urgency is set by four binary variables per vulnerability instance: is the asset publicly exposed, is the CVE in the KEV catalog, can an adversary automate the exploit, and does exploitation yield total or partial control. The sixteen possible combinations map to five tiers.
| Remediation tier | Trigger |
|---|---|
| 3 days + forensic triage | In the KEV and yields total control, agencies must also assess whether they’ve already been compromised |
| 3 days | Other highest-risk combinations, such as publicly exposed, automatable, and total control, even pre-KEV |
| 14 days | Standard accelerated tier for most KEV combinations |
| 60 days | Lower-risk combinations |
| Focus on the next upgrade | No risk criteria met, the deferral tier |
Timelines are dynamic. The moment an asset becomes publicly exposed, or a CVE lands in the KEV, the clock accelerates. That makes continuous knowledge of your own exposure an auditable compliance requirement, not a nice-to-have.
The Two Questions No Scanner Can Answer
CISA publishes answers to three of the four variables. KEV status, exploit automation, and technical impact are provided per CVE through the Vulnrichment program (for many, but not all CVEs). But those answers are generic to the CVE, and one variable comes with no answer sheet at all: asset exposure is the one determination every agency must make for itself.
That determination is harder than it sounds. Exposure isn’t a CMDB field. It is the sum of a dozen moving parts, including a load balancer rule, a WAF exception, a forgotten dev subdomain, or an ephemeral cloud instance that picked up a public IP last Tuesday. Inventories and scanners tell you what’s internet-adjacent on paper. They cannot tell you what an unauthenticated adversary can actually reach and exploit right now. Getting that answer wrong has real consequences: a false “not exposed” silently defangs an urgent 3-day remediation requirement into a 60-day exposure window.
Technical impact has the same problem in a different context. Vulnrichment tells you what a CVE can do in the worst case, anywhere. It cannot tell you what an attacker gets in your environment. A “partial control” SSRF is a footnote until it reaches a cloud metadata service, harvests credentials, and pivots into something no per-CVE rating anticipated. Equally, a “total control” finding behind three layers of segmentation may deserve less panic than its label suggests. A generic rating is an assumption. An exploit chain is evidence, and producing it is the job of AI-powered pentesting run against the systems as they exist today.
Concentration Is the Point, and the Risk
CISA’s own pilot analysis at a large civilian agency found roughly 1% of vulnerability instances in the three-day tier, while more than 60% qualified for deferral. That’s the directive working as designed, and it means the accuracy of the sorting becomes everything. CVSS scores, the backbone of most vulnerability programs for two decades, appear nowhere in the model. Evidence of exploitation, exposure of truth, and demonstrated impact do.
This Won’t Stay Federal
BOD 26-04 binds Federal Civilian Executive Branch agencies, but CISA’s announcement pointed the framework at a much wider audience. Acting Director Nick Andersen said CISA “strongly encourages all partners to adopt similar actions in their vulnerability management policy.”
This feels familiar. BOD 22-01’s KEV catalog was a federal mandate that became the most widely adopted prioritization signal in the industry, used by enterprises, state and local governments, critical infrastructure operators, and allies worldwide. The four-variable model will follow the same curve. For contractors, regulated industries, and anyone in a federal supply chain, aligning before it becomes an expectation is considerably cheaper than retrofitting after.
Why Point-in-Time Testing Cannot Keep Pace with KEV Clocks
Remediation timelines start the moment a CVE enters the KEV catalog. A three-day clock leaves no room to schedule an assessment, scope it, and wait for a report. Penetration testing as a service has already moved the industry away from the single annual engagement; BOD 26-04’s dynamic timelines push that shift to its conclusion.
| Point-in-time testing | Continuous validation |
|---|---|
| Tests one snapshot of the environment | Test assets as they currently run |
| Exposure determined at scan intervals | Exposure validated as it changes, matching the directive’s dynamic clocks |
| New KEV entries trigger reactive scoping | New KEV entries validated against live scope as they land |
| A dated report as attestation | Ongoing exploit evidence as proof |
Compliance clocks are moving at KEV speed. Is your validation? See how continuous pentesting keeps pace.
Human Validation Keeps Speed From Becoming Noise
Running validation continuously raises an obvious question: Does it just produce a stream of alerts nobody can act on? It does if you let automation grade its own homework. AI can find more, faster, but human validation is what gives security teams confidence in what matters. That is the architecture in place: Sara, the Synack Autonomous Red Agent, handles reconnaissance, attack surface mapping, and initial exploit validation at the same tempo as the directive’s “exploit automation” criterion, while the Synack Red Team, 1,500+ vetted researchers, brings the creativity and judgment automation cannot replicate.
- Researchers prove which flagged assets are actually reachable from an unauthenticated position, turning a scanner flag into a defensible exposure determination.
- Attack chaining demonstrates true post-exploitation blast radius, so remediation ranking is backed by demonstrated impact, not a worst-case guess.
- Exploit-verified findings show exactly which paths an attacker could take, concentrating on a three-day forensic triage where compromise is plausible.
- Every finding ships with a documented chain of evidence, the kind that holds up in front of an auditor, an inspector general, or CISA.
Bringing Vulnerability Management Up to Directive Speed
BOD 26-04 doesn’t just change deadlines. It changes what counts as a defensible answer. Strip away the policy language, and the directive is an adversary simulation: how fast can this be weaponized, what can it reach, and what does it yield? Those are the questions a red team asks every day. CISA has now made them the questions a compliance program must answer, continuously and with evidence.
Continuous, human-validated pentesting is built for that pace. It proves which of your “exposed” assets actually are, demonstrates what an attacker really gets, and produces evidence your team can act on the same week it’s generated. Machine speed, human depth — CISA just wrote the requirement.
If BOD 26-04 applies to you, or your customers and regulators will soon expect the same rigor, talk to our Public Sector team about a BOD 26-04 exposure-validation assessment.
This article is for informational purposes only and does not constitute legal advice.
Frequently Asked Questions
A binding operational directive CISA issued on June 10, 2026, requiring federal civilian agencies to prioritize vulnerability remediation based on four risk variables rather than flat KEV deadlines. It revokes and replaces BOD 22-01 and BOD 19-02.
Asset exposure, KEV status, exploit automation, and post-exploitation technical impact. CISA publishes the last three per CVE; agencies must determine asset exposure themselves.
Five tiers: three days with mandatory forensic triage, three days, 14 days, 60 days, or deferral to the next system upgrade–assigned by the combination of the four variables, and accelerating dynamically when exposure or KEV status changes.
Not as a mandate, but CISA’s Acting Director explicitly encouraged all partners to adopt the same practices, and the KEV catalog’s history shows that these frameworks have become de facto industry standards.
BOD 22-01 applied flat deadlines to every KEV entry. BOD 26-04 grades urgency by risk, adds a deferral tier, requires forensic triage for the highest-risk tier, and drops CVSS-style scoring in favor of exploitation-evidence reasoning.
Sara tests continuously at adversary automation speed while the Synack Red Team validates real exposure and demonstrates post-exploitation impact, the two variables no scanner can answer–with exploit evidence fit for auditors. Learn more about AI pentesting.


