BOD 26-04: Prioritizing Security Updates Based on Risk
Vulnerability backlogs don’t lie. Priority lists do.
CISA’s BOD 26-04 replaces CVSS-only scoring with four risk signals evaluated together. Download the whitepaper to see what changes, why it’s harder to operationalize than it looks, and where reachability-based analysis fits.

3 Days
Remediation window when the four criteria are met
4
Risk signals assessed jointly, not additively
2019
Mandate led by the CVSS, replaced after seven years
Summary
- What changed : the directive, in detail
- Why this is harder than it sounds
- Where deterministic attack path analysis fits
- Case study : a worked scenario
- Takeways
What changed
On June 10, 2026, CISA published Binding Operational Directive 26-04, replacing the CVSS-driven remediation mandate in place since 2019. Vulnerabilities are now prioritized on four signals evaluated together like asset exposure, known exploitation, automatability, and technical impact, with a three-day remediation window for anything meeting all four.
Why it’s harder than it looks
Each criterion sounds like a lookup. In practice, each one collapses into the same question: what does your network actually look like right now. A CVE feed and a spreadsheet can’t answer that. It takes modeling the network as a graph of reachability and privilege.
Where deterministic attack path analysis fits
Rather than scoring vulnerabilities individually, this approach models assets, identities, and trust relationships as a graph, and computes, rather than estimates, which vulnerabilities sit on a real, reachable path to a meaningful target. The whitepaper walks through the mechanics and a worked scenario.
Download the whitepaper
Source : https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
