Security warnings routinely use urgent language. The federal government’s Known Exploited Vulnerabilities catalog provides something more concrete: a date by which civilian agencies must complete the required action.
A USA Times analysis of all 1,661 entries in the Cybersecurity and Infrastructure Security Agency catalog available on August 6, 2026 found that the typical deadline was 21 days after a vulnerability entered the catalog. But 80 entries—about 4.8%—allowed three days or less.
Those shortest windows are a distinct signal. They do not necessarily identify the most technically severe software flaws, but they show the cases in which CISA gave agencies exceptionally little time to act after adding a known-exploited vulnerability to the binding catalog.
Batmandir · Guest Passes Step inside for a day. Guest passes from $161/day — brought in by a member. See guest passes →The deadline distribution
For each catalog row, we subtracted dateAdded from dueDate. The median was 21 days. The 25th and 75th percentiles were also 21 days, reflecting how heavily the catalog is concentrated at that standard window.
| Days allowed | Catalog entries | Share |
|---|---|---|
| 1 | 6 | 0.4% |
| 2 | 4 | 0.2% |
| 3 | 70 | 4.2% |
| 4–13 | 33 | 2.0% |
| 14 | 259 | 15.6% |
| 21 | 1,025 | 61.7% |
| 22–180 | 7 | 0.4% |
| 181–184 | 257 | 15.5% |
The minimum was one day and the maximum was 184. The long windows are not evidence that those vulnerabilities were harmless. CISA’s catalog and directives evolved, and some original deadlines were set in bulk. A deadline comparison must therefore be read as an administrative response window, not a universal risk score.
Federal remediation windows in the CISA KEV catalog
Share of 1,661 catalog entries, snapshot downloaded Aug. 6, 2026
4.8%4–13
2.0%14 days
15.6%21 days
61.7%22+ days
15.9%
Why the three-day group deserves attention
A three-day remediation deadline leaves little room for the normal enterprise sequence: inventory affected assets, test the vendor fix, schedule downtime, deploy, validate and document exceptions. When the required action is not a patch but a mitigation or removal, the operational work may be even harder.
For a security team, the useful alert is not simply that a new CVE appeared. It is that a CVE already known to be exploited entered KEV with an unusually short clock. That combination should trigger immediate asset discovery and an executive decision about service interruption, rather than waiting for the next routine patch cycle.
CISA explains that the catalog is the authoritative source of vulnerabilities exploited in the wild and requires federal civilian agencies to remediate them under Binding Operational Directive 22-01. Private organizations are not bound by the federal due dates, but CISA urges all organizations to use the catalog as an input to vulnerability-management prioritization.
What a fast deadline does—and does not—mean
The catalog does not say every organization will be compromised on the due date. Nor does a one-day window prove a vulnerability has a higher CVSS score, affects more products or causes more damage than an entry with 21 days. The deadline may reflect exploitation activity, available remediation, federal exposure, operational considerations or a directive-specific decision that cannot be reconstructed from the CSV alone.
It is also wrong to calculate “days to patch” from the catalog and describe it as how quickly vendors fixed a problem. The two columns measure the time CISA allowed covered agencies after catalog addition. A vendor’s disclosure, patch release and the vulnerability’s first exploitation may have occurred earlier.
The defensible description is narrower: these are the shortest federal remediation windows in the KEV catalog.
A better way to build the morning patch queue
Organizations that already ingest KEV can add a simple deadline tier:
| Tier | Window | Suggested operational response |
|---|---|---|
| Emergency | 1–3 days | Page the owner; identify exposure immediately; document a same-day plan |
| Accelerated | 4–13 days | Start testing outside normal cadence; set daily status |
| Urgent | 14 days | Prioritize over ordinary monthly work |
| Standard KEV | 21 days | Track to completion within the binding-style window |
| Extended | More than 21 days | Verify why the date differs; do not infer low risk |
This is not a substitute for asset context. A three-day vulnerability in software the organization does not run is not its first operational problem. Conversely, a 21-day entry on an internet-facing identity system may demand action long before the catalog deadline.
The first question should therefore be binary: “Are we exposed?” The second is temporal: “How much of CISA’s window remains?”
Reproducibility and changes over time
This result is a snapshot. CISA adds entries and can update existing fields. Anyone citing the numbers should retain the source file, record the retrieval date and publish a hash so a later analyst can identify the exact version used.
Our saved CSV contained 1,661 rows, with catalog addition dates from November 3, 2021 through August 5, 2026. Its SHA-256 hash is d0fa03c120c858869a17bd0f0c5bf0bb8f9202693958e709396e24e4346f4faa.
Rows with invalid or missing dates should be disclosed and excluded. In this snapshot, the distribution was calculated from parseable dateAdded and dueDate values. The cleaned deadline table retains the CVE identifier, vendor, product, both dates, required action and ransomware-use flag so readers can inspect the underlying cases rather than rely on an unexplained chart.
The durable finding
Most KEV entries in the current catalog sit on a 21-day federal clock. That is the norm. The useful exception is the group that does not: 80 vulnerabilities gave agencies no more than three days.
Security teams do not need more generic red banners. They need a queue that distinguishes this week from today. CISA’s two date fields make that possible—as long as users calculate the interval and avoid turning it into a claim the data cannot support.
What we did
Primary source: CISA’s Known Exploited Vulnerabilities Catalog and its downloadable CSV. USA Times calculated calendar days between catalog addition and remediation due date for every parseable row in the August 6, 2026 snapshot. Percentages are rounded and may not sum perfectly. The analysis describes federal response windows, not vendor patch latency or intrinsic severity.




