The KEV remediation window fell from 21 days to three, and the 60-day tier everyone quotes has never existed
Computed from all 1,695 entries in the catalogue. Since BOD 26-04 in June, 60 of 78 additions carry a three-day deadline, and no KEV entry has ever carried a 60-day one.
By Parminder Kumar Sharma · · 8 min read

CISA issued Binding Operational Directive 26-04 on 10 June 2026. It was reported, reasonably, as a move away from patch-everything towards risk-based prioritisation, and several vendor explainers described it as introducing three tiers of three, fourteen and sixty days.
I pulled the Known Exploited Vulnerabilities catalogue and subtracted the date added from the due date on all 1,695 entries. The result is not what the coverage describes, in two different directions.
The window
The median KEV remediation window, and the tier that is not there
Between June 2025 and February 2026, across 178 additions, the median remediation window was 21 days.
From March to 9 June 2026, across 88 additions, it was 14 days.
Since the directive, across 78 additions, it is 3 days. Sixty of those 78 carry a three-day deadline and the other 18 carry fourteen. Nothing else appears at all.
So a directive presented as reducing the patching burden through prioritisation coincides with the most aggressive available deadline becoming the default, on better than three quarters of everything added.
The tier that does not exist
The sixty-day tier is the more interesting finding, because it is not a rounding error or a matter of interpretation. No KEV entry has ever carried a sixty-day deadline.
The complete set of distinct deadline lengths across the entire catalogue, all 1,695 rows and every year, is: 1, 2, 3, 4, 5, 7, 8, 12, 14, 21, 24, 25, 31, 43, 181, 182 and 184 days.
Long windows do exist. They are 181, 182 and 184 days, from the original backlog catalogued under BOD 22-01, and there are 258 entries with a window longer than a month. But there is no 60 anywhere, and the reason is in the directive rather than the data.
The low-risk end of BOD 26-04 is not a deadline at all. Where the risk variables come out favourably, the requirement is to "Fix on system upgrade". That is a disposition, not a clock. The tier being described in coverage as sixty days is a tier that was never specified.
What the due date actually is
This cuts the other way too, and any organisation using KEV as a compliance input needs it.
BOD 26-04 sets the timeline from four variables: whether the asset is publicly exposed, whether the vulnerability is in KEV, whether an adversary can automate every step of exploitation, and whether they gain partial or total control. Three days is the corner case where all four are at their worst.
Crucially, agencies determine their own asset exposure. The directive says they should follow CISA's Internet Exposure Reduction Guidance to answer that question themselves.
So the dueDate in the KEV feed is CISA's calculation for a publicly exposed asset. It is the worst case, published centrally. For an internal asset behind other controls, the same CVE carries a longer timeline decided by the agency. Headlines saying "BOD 26-04 mandates a three-day patch window" are therefore wrong in the opposite direction from the sixty-day explainers.
The clause underneath the three days
There is a second obligation attached to the shortest tier that almost nothing has covered.
Where the timeline carries the phrase "& forensic triage", the agency must both remediate within three days and carry out a forensic triage of the asset to assess whether it has already been compromised.
That is a materially larger ask than patching. Patching a known-exploited flaw on an internet-facing asset is a change control problem. Establishing whether that asset was compromised before you patched it is an investigation, and it is the part that consumes people rather than maintenance windows.
If your own policy mirrors KEV deadlines, this is the clause to read before you mirror the new ones.
What each figure is, and where it comes from
| Figure | Value | Source and caveat |
|---|---|---|
| Median window, Jun 2025 to Feb 2026 | 21 days across 178 additions | Computed from the feed |
| Median window, Mar to 9 Jun 2026 | 14 days across 88 additions | Computed from the feed |
| Median window since 10 Jun 2026 | 3 days across 78 additions | Computed from the feed |
| Share of post-directive entries at 3 days | 60 of 78, or 76.9% | Computed from the feed. The remaining 18 are all 14 days |
| Entries ever carrying a 60-day deadline | Zero | The low-risk disposition in the directive is “fix on system upgrade”, not a 60-day clock |
| Longest windows in the catalogue | 181, 182 and 184 days | The original BOD 22-01 backlog, not a current tier |
| What the published due date represents | CISA’s calculation for a publicly exposed asset | Agencies determine their own asset exposure under the directive, so an internal asset gets a longer timeline |
| Additional duty on the three-day tier | Forensic triage of the asset | Assess whether the system is already compromised, alongside remediation |
What to do about it
Take this with you
If your policy references KEV
- Find out whether your vulnerability management standard says “by the KEV due date”. If it does, your effective SLA moved from roughly three weeks to three days in June, and nobody signed that off.
- Decide whether you are adopting CISA’s exposure assumption or your own. The published date assumes a publicly exposed asset. Applying it to everything, including internal systems, imports the worst case for your whole estate.
- If you do adopt three days for internet-facing assets, budget for the triage as well as the patch. The directive pairs the shortest deadline with a compromise assessment, and that is the expensive half.
- Stop quoting the 60-day tier. It has never appeared in the catalogue and it is not in the directive; the low-risk requirement is to fix on the next system upgrade.
- Recompute this yourself rather than trusting the figures here. The feed is one file, the arithmetic is dueDate minus dateAdded, and it takes about ten lines of code. Any number in this piece should survive that.
- Watch the trend rather than the level. Three medians a year apart is a direction of travel, and if the next quarter sits at three days again then this is the new normal rather than a run of severe entries.
The position
Two opposite errors are circulating about the same directive, and both come from reading a summary rather than the artefact.
One says the new regime relaxes things into a sixty-day tier that does not exist. The other says it mandates a universal three-day patch window, when the published date is a worst-case calculation that agencies are explicitly told to adjust for their own exposure.
What actually happened is narrower and more consequential than either. The centrally published deadline attached to a known-exploited vulnerability has gone from three weeks to three days in about fifteen months, and the shortest tier now applies to three quarters of new entries. For federal agencies that was a deliberate policy decision with reasoning behind it. For everybody else who quietly wired KEV into their own standards, it was a change to their internal SLA that nobody proposed, reviewed or approved.
The feed is public and the calculation is two date fields. It is worth doing before your next audit does it for you.
Sources
- PrimaryKnown Exploited Vulnerabilities catalogue, catalogVersion 2026.09.04, 1,695 entries. All median and distribution figures in this briefing were computed from this fileCISAaccessed 2026-09-05
- PrimaryBinding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, issued 10 June 2026, including the four risk variables, the fix-on-system-upgrade disposition and the forensic triage requirementCISAaccessed 2026-09-05
- PrimaryThe KEV catalogue landing page and its description of how due dates are set for federal civilian executive branch agenciesCISAaccessed 2026-09-05


