← Field notesOne number · 20 Sep 2026

Three days. CISA set that deadline 102 times this year.

When CISA adds a vulnerability to its Known Exploited list it sets a date by which US federal agencies must act. Of the 227 entries added in 2026:

  1. 102 got three days.
  2. 78 got fourteen days.
  3. 44 got twenty-one days.

That clock binds US federal agencies and FedRAMP cloud providers. It does not bind a UK company. But it is the most experienced vulnerability programme in the world telling you how long it thinks you have, in a public file, for free.

If your own remediation policy gives every critical finding thirty days, it is slower than CISA on four out of five of this year's exploited entries. An assessor comparing the two will notice.

Source: CISA Known Exploited Vulnerabilities catalogue v2026.09.16, dueDate minus dateAdded for entries added in 2026, computed 16 Sep 2026. The due dates apply under CISA Binding Operational Directive 26-04 to US federal civilian agencies; they are not a UK obligation.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes