HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Editorial explainer · official sourcesmedium

Patching everything is over: the risk method, explained

In June 2026 CISA issued directive BOD 26-04, changing how US federal agencies decide what to fix first. The rule is no longer "update everything, fast", but "update first what is genuinely risky", by four criteria. It binds US agencies, not Italian companies; but the method is replicable anywhere the patch queue is longer than the time available — that is, almost everywhere. An explainer on how it works and what can be taken from it.

The problem with "patch everything"

Anyone who manages vulnerabilities knows the feeling: the list of updates to apply is longer than the time and hands available. For years the implicit answer was "patch everything, and fast". On paper it is unimpeachable; in practice it produces an undifferentiated queue in which a catastrophic, actively exploited flaw has the same apparent urgency as a theoretical oversight on an internal system no one can reach. When everything is a priority, nothing is.

Directive BOD 26-04, issued by CISA on 10 June 2026, tries to break this pattern for US federal agencies. It supersedes two earlier directives — BOD 22-01, the one behind the Known Exploited Vulnerabilities catalogue, and BOD 19-02 — and shifts the centre of gravity from abstract severity to concrete risk. It does not bind Italian companies as an obligation. But the reasoning it proposes is general.

The four signals that matter

The heart of the directive is a set of criteria for deciding order. Simplifying what CISA states, a vulnerability rises to the top when it is publicly exposed, when it is in the catalogue of actively exploited vulnerabilities, when it is easily automatable at scale, and when it has a severe technical impact. These are four questions, not a single score to accept passively.

  1. 01
    Is it reachable from outside?
    public exposure is the first multiplier
  2. 02
    Is it already exploited (KEV)?
    not a theoretical risk, but an attack under way
  3. 03
    Is it easily automated?
    what scales hits many, fast
  4. 04
    Is the impact severe?
    takeover, code execution, mass theft

When a vulnerability answers "yes" to all four, the directive requires agencies to fix it within three days. It is the same very tight window seen on the most serious entries of the KEV catalogue, and that is no accident: the catalogue is one of the model's input signals.

What a company can take from it

The value of BOD 26-04, for those who are not a federal agency, lies not in the obligation but in the method. Three things transfer. First: use the CISA KEV catalogue as a real priority list, because it lists what someone is actually exploiting, not what could be exploited in theory. Second: weigh exposure alongside severity — a critical flaw on an unreachable system is less urgent than a medium one on an internet-facing service. Third, often overlooked, is the governance part: the directive asks agencies to be able to explain why they fixed certain things before others, and to check — through forensic triage — whether vulnerable systems have not already been compromised. Prioritising is not only speed: it is being able to account for the choices.

An honest caveat. "Patch by risk" does not mean "do not patch the rest": vulnerabilities outside the four criteria still need closing, just on a longer deadline. The model's risk is that someone uses it as an excuse to defer indefinitely whatever is not at the top. But applied well it does something precious under finite resources: it puts time where it is needed most. The sources for the detail are the directive and its implementation guidance, both public on the CISA website.

More dossiers