BOD 26 04
5 articles tagged “BOD 26 04”.
-
This Week in Change Risk — Week of Aug 24, 2026
A CVSS-10.0 Oracle flaw with CISA's tightest three-day deadline, six more KEV entries, GitHub's outage pledge, and PagerDuty's SRE-agent drop.
-
BOD 26-04: Pre-Wire Your Emergency Change Before the Clock
CISA's BOD 26-04 sets a 16-row deadline table. Here is how a CAB pre-authorizes the ECAB so a 3-day KEV clock never catches you improvising.
-
The 3-Day KEV Clock: A CAB Runbook for CVE-2026-8037
CISA gave Progress LoadMaster CVE-2026-8037 a three-day deadline. How a change advisory board runs an emergency change against that clock.
-
CISA BOD 26-04: Risk-Based Patch Deadlines for CABs
CISA BOD 26-04 replaces the flat 14-day KEV clock with 3, 14, and 60-day risk-based deadlines. What change managers and CABs must rebuild by December.
-
CISA's July 21 KEV Batch: How a CAB Should Triage 4 CVEs
CISA added four exploited CVEs on July 21, 2026 — WordPress, Langflow, and DD-WRT. A change manager's triage playbook under the new BOD 26-04 rules.