Since 2021 the United States has kept a public list of the software flaws it knows are being exploited, and attached to every entry is a date by which federal civilian agencies must have fixed it. For most of the list’s life that date was not really a judgement call. Of the 187 flaws added in 2023, 94.7% carried a deadline of exactly 21 days after they were catalogued; in 2024 it was 94.1% of 186, and in 2025 it was 92.2% of 245. The window was a constant, applied almost without exception, and it is often described in coverage as a 15-to-30-day range. In practice it was three weeks, nearly every time.
That constant broke this year. Recomputing the gap between the date added and the due date for all 1,656 entries in the catalogue as published on Wednesday gives a 2026 median of 14 days — but the annual figure hides the shape. Month by month, the median ran 21 days in January and 21 in February, dropped to 14 in March and stayed there through April and May, then dropped again to three days in June and has stayed at three through July. It is a staircase with two steps, not a single cut.
The rule that authorises the short clocks arrived between the steps. CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” on 10 June, revoking the 2021 directive that had set the 21-day standard. Every one of the 39 entries catalogued on or after that date cites the new directive in its required-action field, and their median window is three days. The entries from March, April and May that cut the window to 14 days cite the old one. The operational tightening, in other words, began about three months before the instrument that formalised it.
Short deadlines were not unprecedented before this year — the catalogue contains 41 entries with a window of three days or less added before 10 June, going back as far as a Fortinet flaw catalogued on 31 January 2024. What is new is that they stopped being exceptions. Until March they were scattered; since June they are the rule.
The obvious explanation for a three-day clock would be ransomware, and the catalogue records for each entry whether the flaw is known to be used in ransomware campaigns. It does not support that reading. Among flaws added this year, 10.4% of those given three days or fewer are flagged for known ransomware use, against 11.4% of those given longer — a difference too small to mean anything. The discriminator is freshness instead. Of the entries on the three-day clock, 82.1% carry a vulnerability identifier issued in the same calendar year they were catalogued, against 43.8% of the slower group. CISA is accelerating newly disclosed flaws, not the ones with the worst-known criminal history.
The distinction matters for what agencies are being asked to do. A newly disclosed vulnerability is one where a vendor patch may be hours old, where the fix is least tested, and where an emergency deployment carries the highest chance of breaking something. That is the category being put on the shortest clock. The directive’s own implementation guidance gives agencies until early December to reach full compliance with the new timelines, which is 180 days after issuance — while the three-day due dates have been running in the live catalogue since June, and shorter windows have appeared sporadically since 2024.
None of this is hidden. The catalogue is a single public JSON file, updated most business days, and every field used here — the date added, the due date, the directive cited, the ransomware flag — is published with each entry. What is not published is the summary: CISA does not release the distribution of its own deadlines, so the only way to see the staircase is to compute it.