BOD 26-04: Prioritizing KEV and EPSS Correctly
CISA’s BOD 26-04, effective 10 June 2026, consolidates remediation guidance and supersedes BOD 19-02 and BOD 22-01. Priority is now driven by public exposure, KEV status, exploit automation potential, and technical impact. A blanket “patch everything” mandate is no longer in force.
Key Takeaways
- Directive: BOD 26-04 (10 June 2026) steers remediation via four variables and replaces BOD 19-02 and BOD 22-01 for US FCEB agencies; CISA urges comparable measures for all partners.
- KEV before EPSS: FIRST recommends prioritizing KEV-listed vulnerabilities regardless of EPSS score; the 90th percentile of EPSS is ~0.04 (4 %), while the median CVE population sits at ~0.7 %.
- Triage obligation: For the highest-risk combinations, the policy demands very short deadlines including forensic triage, because patching alone does not evict an already-present attacker.
Related: Anthropic: Claude breached three firms · Codex Security: Open client feeds OpenAI
BOD 26-04 ranks urgency via four risk variables
CISA’s Binding Operational Directive 26-04 (Prioritizing Security Updates Based on Risk), issued 10 June 2026, consolidates remediation guidance and rescinds BOD 19-02 (29 April 2019) and BOD 22-01 (3 November 2021). The directive is mandatory for US FCEB agencies. Acting CISA Director Nick Andersen stresses a focus on highest-risk exposures and advises all partners to adopt comparable measures in their own policies.
What is EPSS? EPSS stands for Exploit Prediction Scoring System. It estimates the probability that a given vulnerability will be exploited within the next 30 days. CVSS, by contrast, measures severity. EPSS is recalculated daily.
Urgency is now governed by four variables: public exposure, Known Exploited Vulnerabilities (KEV) catalog status, exploit automation potential, and technical impact (partial versus total control). Methodologically, BOD 26-04’s Appendix A references the Stakeholder-Specific Vulnerability Categorization (SSVC) framework from CERT/CC and Carnegie Mellon SEI. Low-risk issues may be deferred to the next scheduled system upgrade. The highest-risk combinations require very short deadlines, including forensic triage. The full SLA matrix (Table 1: Remediation Timelines) is available on the CISA site and should be referenced 1:1 in your own plan-do not attempt to reconstruct it.
CISA cites the shortening reaction windows between patch release and exploitation-driven by attacker use of AI-as justification for moving from “patch everything immediately” to risk-focused patching. It also notes that an update alone does not remove an adversary already inside the network. Forensic triage is therefore part of the policy response for the most time-critical cases, not optional follow-up work.
KEV remains the hard trigger for immediate action
CISA urges all organizations to ingest the KEV catalog into their prioritization frameworks and to address KEV-listed vulnerabilities immediately in their vulnerability-management plans. Entry into the KEV catalog requires three criteria: a CVE ID, credible evidence of active exploitation in the wild, and a clear remediation action.
Proof-of-concept code, simple scanning, and security research do not qualify as active exploitation for KEV inclusion, CISA states. This distinction separates KEV from the broader CVE population and turns it into a hard-priority list. For DACH teams, this means linking KEV entries in your asset inventory and ticketing system to your own exposure and control posture-rather than merely archiving them as a notification list. CISA programs such as Vulnrichment and Continuous Diagnostics and Mitigation (CDM) reinforce the same focus on actionable, prioritized signals.
EPSS measures probability, not severity or overall risk
The Exploit Prediction Scoring System (EPSS), under the umbrella of FIRST (Forum of Incident Response and Security Teams), operated by the EPSS Special Interest Group and using scores from Empirical Security, estimates the probability that a published CVE will be exploited in the wild within the next 30 days. The scores are available daily and can be used free of charge.
Prioritization in four steps
- ✓Cross-check all assets against the KEV list and schedule any matches as top priority.
- ✓For the remainder, pull the EPSS value and document the threshold in writing with your team.
- ✓Assess exposure: internet-reachable, authenticated, or internally segmented.
- ✓Only then use the CVSS score as supplementary information-never as the sole driver.
FIRST explicitly defines EPSS as a calibrated probability rather than a severity or full risk score. Presence, reachability, and consequence must be added by the organization itself. For programs looking to move away from CVSS Critical, the approximate EPSS equivalent of the 90th percentile is about 0.04 (4 percent). A threshold of 50 percent deprioritizes the majority of the CVE population; the median sits at roughly 0.7 percent, while the mean is around 2.8 percent.
FIRST cautions against score laundering: multiplying EPSS by ordinal CVSS values does not yield an interpretable combined risk score. EPSS remains useful for the large set of non-KEV CVEs. A low EPSS score and KEV listing are not mutually exclusive. When a CVE is KEV-listed, FIRST recommends prioritizing it regardless of the EPSS score.
Vendor studies reveal limits of score stacks and early-warning assumptions
According to a post by Sıla Özeren Hacıoğlu (Picus Security, April 16, 2026), combining EPSS, the Common Vulnerability Scoring System (CVSS), and CISA KEV can dramatically reduce the urgent prioritization workload-up to “as much as 95 percent,” Picus notes. EPSS alone, however, remains global and unaware of your own controls. Picus further argues that control validation must come before relying on a pure score stack: whether your exploit path is actually blocked depends on your local environment. This expands CISA and FIRST logic but aligns with vendor interests in BAS and control-validation platforms.
Definition · KEV Catalog
The CISA Known Exploited Vulnerabilities Catalog lists vulnerabilities for which exploitation in the wild has been confirmed. An entry is a factual finding rather than a forecast. U.S. federal agencies face binding deadlines tied to it; for everyone else, the list serves as a filter that establishes urgency without model-based assumptions.
Tally Netzer (Nucleus Security, May 12, 2026) reports from a sample of 22 of the 122 KEV additions between October 2025 and March 2026: the median EPSS movement after KEV listing was about 121 times larger than before; the strongest EPSS increase occurred within two days of KEV confirmation. Nucleus argues empirically that teams mistakenly treat EPSS as an early-warning signal, even though the rise for many KEV CVEs only happens after public KEV confirmation. This aligns with FIRST’s stance: EPSS is a population-level probability and not a substitute for KEV or local context.
Vulnerability management audit steps in the DACH region
The KEV catalogue is a fixed input for the prioritisation framework: every new KEV entry triggers asset reconciliation, exposure review and a remediation ticket with owner and deadline. EPSS is used to rank the non-KEV volume, for example using the 90th percentile as a working threshold, without multiplying CVSS and EPSS. The four BOD variables can be mapped to custom policy fields: internet-exposed yes/no, KEV yes/no, automation potential, partial or total control impact.
For the highest risk class, forensic triage steps must be defined in advance: log and endpoint visibility, IOC search, isolation and proof that no attacker was active before the patch. Low-risk combinations may be deferred to the next system upgrade if this is documented and approved. Board and supervisory reports benefit from metrics such as the share of open KEV hits by exposure, median time to remediation for KEV and the share of the CVE population above the chosen EPSS threshold.
Teams using the CVSS, EPSS and KEV stack should treat control validation and reachability as the fourth and fifth layers. This keeps prioritisation interpretable and avoids the assumption that a rising EPSS value can replace the KEV trigger or the local asset situation.
Frequently Asked Questions
Does BOD 26-04 also apply to companies in the DACH region?
BOD 26-04 mandates controls for US FCEB agencies. Acting CISA Director Nick Andersen advises all partners to adopt comparable risk-focused measures in their own policies. For DACH organisations, the text serves as a robust blueprint for vulnerability management, not German law.
When does a CVE enter the CISA KEV catalogue?
According to CISA, three criteria must be met: a CVE ID, credible evidence of active exploitation in the wild and a clear remediation action. Proof-of-concept code, scanning reports and pure security research do not qualify as active exploitation for KEV inclusion.
How should EPSS be used alongside KEV and CVSS?
FIRST positions EPSS as a calibrated 30-day probability of exploitation. Teams prioritise KEV-listed items regardless of EPSS score. EPSS is used to rank the large non-KEV volume. Multiplying EPSS by CVSS (score laundering) does not, according to FIRST, produce an interpretable risk score.
Why isn’t patching enough in the most critical cases?
BOD 26-04 emphasises that an update does not remove an attacker already present. For the highest-risk combinations, very short remediation deadlines-including forensic triage-are required. CISA also points to shortened attacker response windows enabled by AI.
What EPSS threshold works as a practical cut-off?
FIRST suggests using the 90th percentile at roughly 0.04 (4 percent) as a guide. A 50 percent threshold would deprioritise the majority of the CVE population; the median and mean sit at about 0.7 percent and 2.8 percent respectively. The threshold must be complemented by the presence, reachability and consequence specific to your environment.
Editor’s Picks
- Anthropic: Claude cracks three firms
- Codex Security: Open client fuels OpenAI
- CERT-Bund rescinds Zabbix warning after 24 hours
More from the MBF Media Network
Image source: AI-generated (August 2026)
Translated from the German original using artificial intelligence. The German version is authoritative.
Further reading
Attacker accounts remain active after the Artifactory patch
Admin accounts, backdoors and remote access services survive the update. Attacks on Artifactory and PaperCut show what still needs to be checked after patching.
Rehearse the IT outage before no one is left to decide
Two hours analog, fixed roles and an annual calendar let you rehearse a real outage before operations stop.
Microsoft Teams: Android Path Traversal Runs Attacker Code
Microsoft Teams for Android allows path traversal. NVD added CVE-2026-65768 on August 11, 2026. Microsoft rates it 8.8, NVD rates 9.8.