CISA directive revamps how agencies prioritize vulnerable systems
traffic_analyzer/Getty Images
ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW
June 10, 2026 02:28 PM ET
The move is part of CISA’s response “to the current threat landscape where AI software services can assist threat actors to find and exploit vulnerabilities,” the agency says.
The Cybersecurity and Infrastructure Security Agency released a binding directive Wednesday requiring federal agencies to rethink how they prioritize vulnerability fixes across government networks.
The directive sets remediation deadlines based on several factors, including whether a flaw is publicly exposed, already known to be exploited, automatable by attackers or capable of giving hackers control of an affected system.
It establishes new timelines to patch security flaws, from three days for the highest-risk vulnerabilities to 60 days for lower-priority items. Some vulnerabilities that are not publicly exposed, not known to be exploited and not automatable by adversaries can be deferred until the affected system receives...
Copyright of this story solely belongs to nextgov.com. To see the full text click HERE