What Happened
Federal Agencies Must Update Vulnerability Management Policies
The US Cybersecurity and Infrastructure Security Agency (CISA) has announced a new directive requiring federal agencies to prioritize patching high-risk security flaws. The directive, known as Binding Operational Directive 26-04, builds on previous efforts to advance priorities in securing federal networks. Federal agencies must review and update their vulnerability management policies, prioritize remediation of security weaknesses, and monitor updates to the Known Exploited Vulnerabilities (KEV) catalog. This development was first reported by SecurityWeek.