Across the nine CVEs CISA added to the Known Exploited Vulnerabilities catalog on 26 and 27 August, the “required action” text is the same on a three-day deadline as on a 14-day one — which means the record gives agencies the date but not the obligation attached to it.
What happened
CISA made two additions to the Known Exploited Vulnerabilities catalog this week: six CVEs on 26 August 2026 and three more on 27 August. We pulled the records for those additions from NVD’s API, which republishes CISA’s catalog fields verbatim, and compared them field by field.
The due dates fall into two groups:
| CVE | CISA vulnerability name | Added | Due | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer | 2026-08-26 | 2026-08-29 | 9.8 |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | 2026-08-26 | 2026-08-29 | 8.8 |
| CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | 2026-08-27 | 2026-08-30 | 9.8 |
| CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | 2026-08-26 | 2026-09-09 | 9.8 |
| CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | 2026-08-26 | 2026-09-09 | 7.8 |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | 2026-08-26 | 2026-09-09 | 7.8 |
| CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | 2026-08-26 | 2026-09-09 | 5.1 |
Three days for some, 14 for others. That much is visible. What is not visible is why, and the record does not help.
The cisaRequiredAction field is the only prose CISA attaches to a catalog entry. On CVE-2019-1068, due in three days, it reads:
“Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s "Forensics Triage Requirements" (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.”
On CVE-2022-0995, due in 14 days, it reads the same. Word for word, including the citation of “Forensics Triage Requirements.” The same string appears on CVE-2026-8452 and CVE-2023-49105, both on three-day clocks, and on CVE-2021-23758, on a 14-day clock. Five records, two deadline bands, one sentence of guidance.
Severity does not separate the groups either. CVE-2021-23758 carries a CVSS v3.1 base score of 9.8 and got 14 days. CVE-2019-1068 carries 8.8 and got three. A 7.8 Linux kernel flaw and a 9.8 Citrix flaw were added on the same day to different bands.
Why it matters
None of this is a scandal, and none of it means CISA assigned the wrong dates. Under BOD 26-04, deadlines are not supposed to track severity. The directive derives them from four binary variables — whether the asset is internet-exposed, whether the vulnerability is in the KEV catalog, whether exploitation is automated, and whether the technical impact is total or partial — and sorts the results into four bands: three days, 14 days, 60 days, and a deferral tier where the fix waits for the next scheduled system upgrade. Some three-day assignments carry an additional forensic-triage obligation. A 9.8 landing in the 14-day band and an 8.8 in the three-day band is the model working as designed, not a mistake.
The problem is that an agency cannot get from the record to the obligation. The authoritative mapping from those four variables to those four bands is published in the directive as Table 1, in Appendix A, as PNG images with no alt text. It is not machine-readable, it is not accessible to a screen reader, and the vendors who have transcribed it by eye disagree with one another about which combinations earn three days. That was already the situation. What this week’s additions show is that the catalog entry does not close the gap: the due date is there, and the reasoning is not, and the one field that might have carried it says the same thing on every entry regardless of band.
That matters most for the forensic-triage obligation, which is the part with real operational weight. The directive’s own language is that the “& forensic triage” marking “means that the agency must complete remediation or mitigation action within the timeline (three days) and carry out a forensic triage of the asset to assess whether the system is compromised.” Patching a server and forensically triaging it are different jobs, done by different people, on different budgets. An agency reading a KEV entry sees a citation of CISA’s “Forensics Triage Requirements” and might reasonably conclude the triage applies. It appears identically on entries where the deadline alone shows the asset cannot be in the three-day-plus-triage band.
We made exactly that mistake this afternoon, in a story published at 3:56 p.m. Central and corrected at 4:03. We read the citation as a signal about the band. It is not one. We are describing our own error here because the inference is an easy one to make from the record as published, and because we would rather show the reasoning than quietly fix it.
There is one more thing in that boilerplate worth reading twice. The final sentence says “Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.” Internet exposure is one of the four variables the deadline is derived from. CISA has already applied some determination of it in order to publish a date, and then tells the agency that evaluating it is the agency’s responsibility. Both can be true — CISA can be assigning a default for the general case while the agency assesses its own instances — but the text does not say which, and an agency whose asset is not internet-exposed has no published basis for concluding that a different deadline applies to it.
The practical effect is that the KEV catalog remains excellent at the thing it was built for, publishing dates, and is being asked to carry something it was not built for. Under the old BOD 22-01 regime, revoked on 10 June 2026, one due date meant one obligation and the required-action text could be boilerplate without losing anything. Under a directive with four bands and a conditional forensic duty, the same field is now the only prose on an entry whose obligations vary. It has not changed to match.
What to do
Read the due date, not the prose. As of this week’s additions, the cisaActionDue field is the only part of a catalog entry that varies with the band. The required-action text is constant and carries no per-entry information. Any tooling that parses it for triage signals is parsing a template.
Do not infer the forensic obligation from the entry. If a three-day deadline appears on an asset you own, the question of whether a forensic triage is also owed has to be settled from BOD 26-04 itself, or by asking CISA. We are not printing a mapping here, and we would treat any vendor blog that prints one as unverified — the transcriptions in circulation conflict.
Private-sector adopters should know what they are adopting. CISA encourages voluntary adoption of BOD 26-04 outside the federal civilian branch. An organization that adopts it is committing to a schedule whose authoritative form is a screenshot. That is workable if you treat every three-day-eligible asset as also owing triage, and expensive if you do.
Track the seven CVEs above on their own dates. Three fall this weekend: 29 August for the Citrix NetScaler and Microsoft SQL Server issues, 30 August for ownCloud. The remaining four are due 9 September.
Sourcing note
Every field in the table and every quotation of required-action text comes from NVD’s API records for the individual CVEs (services.nvd.nist.gov/rest/json/cves/2.0?cveId=<CVE>), which republish CISA’s catalog fields verbatim — NIST carrying a government primary source. cisa.gov returns 403 to automated fetching and blocked direct requests for both the 26 and 27 August alert pages, so the catalog pages themselves were not read and the KEV catalog JSON was not retrieved.
Required-action strings were read and compared for five CVEs: CVE-2019-1068, CVE-2026-8452, CVE-2023-49105, CVE-2021-23758 and CVE-2022-0995. They were identical as returned by the API. The two Red Hat entries, CVE-2015-3246 and CVE-2015-5287, appear in the table on their dates and scores, which were read the same way; their required-action text was not separately compared, so the “identical” claim covers five entries, not seven.
CISA’s 26 August alert is titled “CISA Adds Six Known Exploited Vulnerabilities to Catalog” and the 27 August alert “CISA Adds Three Known Exploited Vulnerabilities to Catalog.” NVD lags the catalog by hours, and this check reconstructed the batches from records modified in that window rather than from the catalog itself; the sixth entry from 26 August and two of the three from 27 August are accounted for by CVEs this site covered separately today, but that reconciliation is not primary-sourced.
The description of BOD 26-04’s four variables, four bands and forensic-triage definition is from the directive’s own text. We have not read Table 1 in Appendix A, which is published as images, and this story asserts no mapping between variable combinations and deadline bands. Unresolved: whether the required-action boilerplate predates BOD 26-04 or was introduced with it, and whether CISA publishes the per-entry band determination anywhere machine-readable.

Leave a Reply