P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

The KEV remediation window fell from 21 days to three, and the 60-day tier everyone quotes has never existed

Computed from all 1,695 entries in the catalogue. Since BOD 26-04 in June, 60 of 78 additions carry a three-day deadline, and no KEV entry has ever carried a 60-day one.

By Parminder Kumar Sharma · · 8 min read

A pair of heavy brushed-steel doors standing almost closed in a dark concrete room, with a narrow vertical sliver of hard white light spilling through the gap and laying a thin bright wedge across the floor.

CISA issued Binding Operational Directive 26-04 on 10 June 2026. It was reported, reasonably, as a move away from patch-everything towards risk-based prioritisation, and several vendor explainers described it as introducing three tiers of three, fourteen and sixty days.

I pulled the Known Exploited Vulnerabilities catalogue and subtracted the date added from the due date on all 1,695 entries. The result is not what the coverage describes, in two different directions.

The window

The median KEV remediation window, and the tier that is not there

THE MEDIAN KEV REMEDIATION WINDOW, AND THE TIER THAT IS NOT THEREComputed from all 1,695 entries in the catalogue at version 2026.09.04.0d5d10d15d20dJune 2025 to February 2026n = 178 additions21 daysMarch to 9 June 2026n = 88 additions14 daysSince BOD 26-04, 10 June 2026n = 78 additions3 daysThe 60-day tier in the explainersn = 0, in the whole catalogueno KEV entry has ever carried oneSince 10 June, 60 of 78 additions carry a three-day deadline. The most aggressive tier became the default.The directive was reported as prioritisation that would reduce the patching burden. On the catalogue, it did the opposite.
Long windows do exist historically, but they are 181, 182 and 184 days, from the original 2021 and 2022 backlog, not 60. The reason 60 never appears is that the low-risk end of BOD 26-04 is not a deadline at all: it is an instruction to fix on the next system upgrade.
Computed directly from the CISA KEV JSON feed at catalogVersion 2026.09.04, released 4 September 2026, by taking dueDate minus dateAdded on every entry and the median per period.

Between June 2025 and February 2026, across 178 additions, the median remediation window was 21 days.

From March to 9 June 2026, across 88 additions, it was 14 days.

Since the directive, across 78 additions, it is 3 days. Sixty of those 78 carry a three-day deadline and the other 18 carry fourteen. Nothing else appears at all.

So a directive presented as reducing the patching burden through prioritisation coincides with the most aggressive available deadline becoming the default, on better than three quarters of everything added.

The tier that does not exist

The sixty-day tier is the more interesting finding, because it is not a rounding error or a matter of interpretation. No KEV entry has ever carried a sixty-day deadline.

The complete set of distinct deadline lengths across the entire catalogue, all 1,695 rows and every year, is: 1, 2, 3, 4, 5, 7, 8, 12, 14, 21, 24, 25, 31, 43, 181, 182 and 184 days.

Long windows do exist. They are 181, 182 and 184 days, from the original backlog catalogued under BOD 22-01, and there are 258 entries with a window longer than a month. But there is no 60 anywhere, and the reason is in the directive rather than the data.

The low-risk end of BOD 26-04 is not a deadline at all. Where the risk variables come out favourably, the requirement is to "Fix on system upgrade". That is a disposition, not a clock. The tier being described in coverage as sixty days is a tier that was never specified.

What the due date actually is

This cuts the other way too, and any organisation using KEV as a compliance input needs it.

BOD 26-04 sets the timeline from four variables: whether the asset is publicly exposed, whether the vulnerability is in KEV, whether an adversary can automate every step of exploitation, and whether they gain partial or total control. Three days is the corner case where all four are at their worst.

Crucially, agencies determine their own asset exposure. The directive says they should follow CISA's Internet Exposure Reduction Guidance to answer that question themselves.

So the dueDate in the KEV feed is CISA's calculation for a publicly exposed asset. It is the worst case, published centrally. For an internal asset behind other controls, the same CVE carries a longer timeline decided by the agency. Headlines saying "BOD 26-04 mandates a three-day patch window" are therefore wrong in the opposite direction from the sixty-day explainers.

The clause underneath the three days

There is a second obligation attached to the shortest tier that almost nothing has covered.

Where the timeline carries the phrase "& forensic triage", the agency must both remediate within three days and carry out a forensic triage of the asset to assess whether it has already been compromised.

That is a materially larger ask than patching. Patching a known-exploited flaw on an internet-facing asset is a change control problem. Establishing whether that asset was compromised before you patched it is an investigation, and it is the part that consumes people rather than maintenance windows.

If your own policy mirrors KEV deadlines, this is the clause to read before you mirror the new ones.

What each figure is, and where it comes from

FigureValueSource and caveat
Median window, Jun 2025 to Feb 202621 days across 178 additionsComputed from the feed
Median window, Mar to 9 Jun 202614 days across 88 additionsComputed from the feed
Median window since 10 Jun 20263 days across 78 additionsComputed from the feed
Share of post-directive entries at 3 days60 of 78, or 76.9%Computed from the feed. The remaining 18 are all 14 days
Entries ever carrying a 60-day deadlineZeroThe low-risk disposition in the directive is “fix on system upgrade”, not a 60-day clock
Longest windows in the catalogue181, 182 and 184 daysThe original BOD 22-01 backlog, not a current tier
What the published due date representsCISA’s calculation for a publicly exposed assetAgencies determine their own asset exposure under the directive, so an internal asset gets a longer timeline
Additional duty on the three-day tierForensic triage of the assetAssess whether the system is already compromised, alongside remediation
All catalogue figures computed from the CISA KEV JSON feed at catalogVersion 2026.09.04. Directive text quoted from BOD 26-04 as published.

What to do about it

Take this with you

If your policy references KEV

  • Find out whether your vulnerability management standard says “by the KEV due date”. If it does, your effective SLA moved from roughly three weeks to three days in June, and nobody signed that off.
  • Decide whether you are adopting CISA’s exposure assumption or your own. The published date assumes a publicly exposed asset. Applying it to everything, including internal systems, imports the worst case for your whole estate.
  • If you do adopt three days for internet-facing assets, budget for the triage as well as the patch. The directive pairs the shortest deadline with a compromise assessment, and that is the expensive half.
  • Stop quoting the 60-day tier. It has never appeared in the catalogue and it is not in the directive; the low-risk requirement is to fix on the next system upgrade.
  • Recompute this yourself rather than trusting the figures here. The feed is one file, the arithmetic is dueDate minus dateAdded, and it takes about ten lines of code. Any number in this piece should survive that.
  • Watch the trend rather than the level. Three medians a year apart is a direction of travel, and if the next quarter sits at three days again then this is the new normal rather than a run of severe entries.

The position

Two opposite errors are circulating about the same directive, and both come from reading a summary rather than the artefact.

One says the new regime relaxes things into a sixty-day tier that does not exist. The other says it mandates a universal three-day patch window, when the published date is a worst-case calculation that agencies are explicitly told to adjust for their own exposure.

What actually happened is narrower and more consequential than either. The centrally published deadline attached to a known-exploited vulnerability has gone from three weeks to three days in about fifteen months, and the shortest tier now applies to three quarters of new entries. For federal agencies that was a deliberate policy decision with reasoning behind it. For everybody else who quietly wired KEV into their own standards, it was a change to their internal SLA that nobody proposed, reviewed or approved.

The feed is public and the calculation is two date fields. It is worth doing before your next audit does it for you.

Sources

  1. PrimaryKnown Exploited Vulnerabilities catalogue, catalogVersion 2026.09.04, 1,695 entries. All median and distribution figures in this briefing were computed from this fileCISAaccessed 2026-09-05
  2. PrimaryBinding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, issued 10 June 2026, including the four risk variables, the fix-on-system-upgrade disposition and the forensic triage requirementCISAaccessed 2026-09-05
  3. PrimaryThe KEV catalogue landing page and its description of how due dates are set for federal civilian executive branch agenciesCISAaccessed 2026-09-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.