The Cybersecurity and Infrastructure Security Agency has issued a new Binding Operational Directive, BOD 26-04, that shifts federal civilian agencies toward a risk-based approach to patching software flaws amid concerns that AI-enabled tools are accelerating attacks. The policy requires agencies to align their vulnerability management programs around four factors: how exposed an asset is, whether a flaw appears in CISA’s Known Exploited Vulnerabilities catalog, the availability of automated exploitation, and the likely technical impact if an intrusion occurs.
The directive consolidates and updates earlier mandates focused on internet-facing systems and known exploited bugs, recalibrating urgency levels so teams concentrate on the most dangerous weaknesses and avoid spending cycles on lower-risk issues.
“CISA is empowering federal civilian agencies to focus their efforts on the areas of highest risk and defer patching lower priority vulnerabilities. This Directive provides clear definitions, timelines, and criteria that enhances transparency, predictability and agencies’ resource planning to execute more effective vulnerability remediation,” said Acting CISA Director Nick Andersen. “CISA continues our work to transform the federal enterprise to be more resilient to sophisticated and persistent cyber threats. CISA is leading and collaborating with federal civilian agencies to stay ahead of our adversaries as tactics, technologies and vulnerabilities change. While this Directive is a mandate for federal agencies, CISA strongly encourages all partners to adopt similar actions in their vulnerability management policy.”
Acknowledging that adversaries may use AI services to find and exploit weaknesses faster than before, CISA added expectations for agencies to check whether systems were compromised before patches are applied. The agency notes that installing a fix does not remove an intruder, making post-patch containment and investigation a required part of risk reduction.
CISA says the move aligns with a recent executive order on AI innovation and security and is intended to speed protection of civilian government systems. The agency will monitor compliance, measure progress and provide support as needed. While binding for federal civilian entities, CISA also urged other organizations to adopt similar, risk-prioritized vulnerability management practices.






