Tag
Vulnerability Management
3 articles tagged “Vulnerability Management”.
-
CISA BOD 26-04: Risk-Based Patch Deadlines for CABs
CISA BOD 26-04 replaces the flat 14-day KEV clock with 3, 14, and 60-day risk-based deadlines. What change managers and CABs must rebuild by December.
-
CISA's July 21 KEV Batch: How a CAB Should Triage 4 CVEs
CISA added four exploited CVEs on July 21, 2026 — WordPress, Langflow, and DD-WRT. A change manager's triage playbook under the new BOD 26-04 rules.
-
How to Read a CISA KEV Entry and What to Do Next
A field-by-field guide to CISA KEV catalog entries, BOD 22-01 obligations, and a 24-hour runbook for when a new KEV drops.