"Not All Vulnerabilities Matter." The Federal Government Just Made It Official.
- Jacob Hughes
- 7 days ago
- 4 min read
How the 2026 shift in U.S. vulnerability policy validates the way LARCK already prioritizes patching for your fleet.

The quote that changes the conversation
In August 2026, Lindsey Cerkovnik, CISA’s Branch Chief for Vulnerability Response, said something out loud that security teams have known for years but rarely admitted:
“Not all vulnerabilities matter. Not all vulnerabilities matter at the same level.”
For anyone who has ever stared at a scanner dumping thousands of “critical” findings across a client fleet, that sentence lands hard. For years, the industry’s default answer to a new CVE was “patch it, and patch it fast.” The problem is that when everything is urgent, nothing is. Teams burn out chasing CVSS 9.8 scores on software that is not internet-facing, not exploited, and not going anywhere, while the one flaw that is actually being used in the wild waits in the same undifferentiated pile.
The federal government has now formally moved off that model. And the model it moved to is the one LARCK was built on.
What actually changed in 2026
Three things happened this year that, taken together, mark a real turning point in how the United States thinks about vulnerabilities.
1. CISA issued a binding directive that ends “patch everything equally.”On June 10, 2026, CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” replacing blanket patch mandates with risk-based deadlines for Federal Civilian Executive Branch agencies. Vulnerabilities that meet all four of the directive’s high-risk criteria must be remediated within 3 days; lower-priority flaws get up to 60 days; and the rest can be deferred until a scheduled upgrade.
Every vulnerability is judged on four questions:
Is the affected system exposed to the internet?
Are threat actors exploiting the flaw (for example, is it on CISA’s Known Exploited Vulnerabilities catalog)?
Is the exploit automatable?
Does exploitation grant an attacker at least partial control of the system?
According to CISA’s analysis of one large civilian agency, as reported by Nextgov/FCW, only about 1% of vulnerability instances qualified for the 3-day tier, while more than 60% could be deferred. In a real environment, the genuinely urgent slice was roughly one in a hundred.
Chris Butera, CISA’s Acting Executive Assistant Director for Cybersecurity, tied the aggressive clock to AI-assisted attackers: “Defenders cannot afford to take weeks to patch systems that can be autonomously exploited en masse.”
2. Congress moved to make the CVE program permanent.After a near-death funding scare in April 2025, when U.S. funding for MITRE’s CVE program briefly lapsed and was only restored after industry outcry, Representatives Delia Ramirez and George Whitesides introduced an amendment to the FY2027 defense authorization bill to formally house CVE inside CISA, mandate a modernization plan with NIST, and, notably, make vulnerability enrichment a formal part of the mission. Moira Bergin, the Democratic staff director for the House Homeland Security Committee’s cybersecurity subcommittee, summed up why it matters: “While CISA is certainly authorized to execute this program, it’s not specifically tasked with doing it, which, as an oversight committee, makes it harder for us to hold an agency accountable.” Raw CVE identifiers, in other words, are no longer treated as enough on their own.
3. The program went global.The European Union Agency for Cybersecurity (ENISA) became an official CVE “Root” authority in November 2025 and has said it intends to advance toward top-level status alongside CISA and MITRE. The direction of travel is a more federated, resilient vulnerability ecosystem, rather than one that hangs on a single feed from a single contract.
There is one more theme the policy conversation keeps returning to: record quality. Officials including Bob Lord, a former Senior Technical Advisor in CISA’s Cybersecurity Division, have argued that vulnerability data needs to be higher quality and machine-readable at the source, because AI is shortening the window between a patch dropping and an exploit landing. That enrichment layer is the reason LARCK exists: false-positive detection, separating OS flaws from software flaws, and resolving the actual patch target instead of forwarding a raw feed to a technician.
The bottom line
The headline out of Washington this year was not really about CVE program plumbing. It was a public, top-down statement that severity is not the same as priority, that context is where the value is, and that the smart move is to fix the vital few and defer the trivial many.
This is not a new idea to us. It is the foundation that LARCK was built on.
LARCK delivers SSVC-based, fleet-relative CVE prioritization for MSPs, natively integrated with Lansweeper. It is built on the CISA SSVC Deployer model, the same decision methodology BOD 26-04 draws on. LARCK is an independent commercial product and is not affiliated with, sponsored by, or endorsed by CISA. Statements attributed to government officials are quoted from the public sources listed below.
Sources
CISA, “CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities” (BOD 26-04 announcement, June 10, 2026): cisa.gov
Cybersecurity Dive, “CISA gives agencies new vulnerability remediation deadlines that take risk levels into account” (Butera quotes, June 2026): cybersecuritydive.com
Nextgov/FCW, “CISA directive revamps how agencies prioritize vulnerable systems” (1% / 60% figures, June 2026): nextgov.com
Nextgov/FCW, “CISA cautions against rigid rules for future cyber vulnerability program” (Cerkovnik, August 2026): nextgov.com
Nextgov/FCW, “Planned NDAA amendment would codify CISA’s role in cyber vulnerability program” (Bergin, June 2026): nextgov.com
Nextgov/FCW, “EU wants to support the bedrock of the cyber vulnerability program” (ENISA, March 2026): nextgov.com



Comments