CISA BOD 26-04 · Prioritizing Security Updates Based on Risk

Three days. The new patch window when a flaw hands over total control.

On 3 August CISA gave federal agencies three days to fix an exploited N-able N-central bypass that handed attackers god mode over every endpoint the console manages. Five weeks later a CVSS 10 flaw in the same product got the same three days. If you run IT for federal customers, that is now the clock you are measured against. This briefing is the position as it stands, written for security leaders at federal contractors and MSPs.

3 KEVs in N-central since 3 Aug3-day window for Tiers 1 and 2Full compliance due Dec 2026

Get the briefing pack

The five tiers, the four variables that set your clock, the N-central timeline, and how a directive aimed at agencies reaches contractors and MSPs. Short, no vendor pitch.

We will email you the pack. No sequence you cannot leave in one click.

Five weeks, three KEVs, one console

N-central is the remote monitoring and management platform MSPs use to run their clients' estates. Since July it has given CISA three reasons to start the three-day clock.

31 Jul 2026

Exploitation starts

CVE-2026-18577, an authentication bypass left behind by an incomplete fix for CVE-2026-18556. Attackers get full admin on the N-central console, then use Take Control to reach managed endpoints and drop Cloudflare tunnels for persistence.

3 Aug 2026

KEV listed. Agencies get 3 days

CISA adds it to the Known Exploited Vulnerabilities catalog with a 6 August deadline. On the same day, 28.6% of observed self-hosted N-central servers were still exposed and unpatched.

8 Sep 2026

Again. CVSS 10, no login needed

CVE-2026-86218, pre-auth remote code execution in the same console. KEV on 8 September, federal deadline 11 September. Fixed in 2026.3 Hotfix 4, the fourth hotfix in five weeks.

Four questions set your clock

BOD 26-04 replaces BOD 22-01 and 19-02. Instead of one deadline for everything in KEV, each finding gets a window from four variables. Agencies must meet the full tiered timelines by early December 2026.

01

Publicly exposed?

Reachable from the internet. You decide, and you have to be able to show it.

02

In KEV?

CISA has evidence it is being exploited in the wild.

03

Automatable?

An attacker can exploit it at scale without a human in the loop.

04

Total control?

Exploitation hands over the whole system, not part of it.

Tier 1

3 days + forensic triage

In KEV and gives an attacker total control of the system. Patch, and check you were not already breached.

Tier 2

3 days

High-risk combinations: publicly exposed, automatable, total control.

Tier 3

14 days

Most KEV entries, plus selected high-risk vulnerabilities that are not in KEV.

Tier 4

60 days

Lower-risk combinations, such as non-exposed assets with partial control.

Tier 5

Fix on upgrade

Meets none of the risk criteria. Deferral permitted.

At CISA's pilot agency about 1% of vulnerability instances landed in the three-day tiers, and more than 60% qualified to wait for the next upgrade. The directive is not “patch everything faster”. It is “know which 1%”.

Not an agency? It still reaches you.

BOD 26-04 binds Federal Civilian Executive Branch agencies only. It reaches contractors and MSPs through the systems they run, the contracts they sign and the tools they depend on.

01

You run agency systems

If you operate, host or administer systems for a civilian agency, its three-day clock is the one your service is measured against.

02

Primes are writing KEV into addenda

Tier-1 primes increasingly reference the KEV catalog directly in supplier security terms. That obligation sits in your contract, not the directive.

03

RFPs follow directives

BOD 22-01's KEV model found its way into contracts and questionnaires. Expect the same for 26-04's tiers within one to three years.

04

Your RMM is the prize

N-central manages other people's infrastructure. One console compromise reaches every client estate behind it. That is why attackers keep coming back to it.

Cyber policies that define cover by reference to “known vulnerabilities” can now turn on a KEV listing date. Worth reading your wording before a claim does it for you.

What you get

From “are we exposed?” to a defensible position.

01

Your tier list, every asset

Every open finding sorted into the five BOD 26-04 tiers, so you know what is three days, fourteen, sixty or next upgrade.

02

Exposure you can prove

Internet-facing assets identified and kept current. It is the variable that moves most findings between tiers.

03

A dollar figure on what is left

What the remaining exposure is worth. The number a board can act on and an underwriter will recognise.

04

KEV matched to your stack

New KEV entries checked against what you actually run, so the clock starts on your side the day it starts for CISA.

05

Triage evidence, timestamped

For Tier 1 findings: what you checked, when, and what you found. The record a prime or an agency will ask for.

06

Defensible deferral

Most findings can wait for the next upgrade. Show the reasoning, so waiting is a decision on record rather than a gap.

What is inside

  • The five tiers and four variables, as a one-page decision table
  • The N-central timeline: three KEVs in five weeks, and what attackers did once they were in
  • How a directive aimed at agencies reaches contractors, primes' suppliers and MSPs
  • The phase dates, and what agencies must have in place by December 2026
  • Tier 1 forensic triage: what three days means when you must also check you were not breached
  • The insurance angle: KEV dates and “known vulnerability” wording in cyber policies
  • A three-day readiness checklist for your own estate

CISA tells you which 1% to fix in three days. We tell you what the other 99% is worth.

Astragar scores every finding on the same variables BOD 26-04 uses (exposure, exploitation, automation, impact) and puts a dollar figure on the risk that remains. Your tier list for the auditor, your number for the board, and the evidence an underwriter recognises.

Book a 20-minute exposure check

This pack is a business briefing, not legal advice. BOD 26-04 binds Federal Civilian Executive Branch agencies; what applies to you depends on your contracts. Position as of 5 October 2026.

Sources: CISA BOD 26-04 (10 June 2026) and KEV catalog; N-able advisories; Huntress, Rapid7, runZero and watchTowr research; The Register.

©Astragar All rights reserved.