RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / From the archive · 3 November 2021 event · prepared 16 September 2026

A directive replaced severity scores with evidence of exploitation

BOD 22-01 requires federal agencies to patch by confirmed exploitation, not by CVSS score alone.

Visual for this record: A directive replaced severity scores with evidence of exploitation
Visual published by reg4tech.com, shown for identification of the record. Credit: reg4tech.com · source page ↗ Rights: owner-review-pending.

What happened

On 3 November 2021, the Cybersecurity and Infrastructure Security Agency issued Binding Operational Directive 22-01, requiring federal civilian agencies to remediate vulnerabilities listed in a new Known Exploited Vulnerabilities catalogue on a fixed schedule rather than according to a severity score. A vulnerability qualifies for the catalogue only if it has an assigned CVE identifier, clear remediation guidance such as a vendor patch, and reliable evidence that it has actually been exploited, not merely that it theoretically could be. The directive set two weeks to patch newly catalogued vulnerabilities discovered from 2021 onward, and six months for older ones, with agencies required to report on their status.

Confidence and limits

The directive's own text and CISA's current description of the catalogue agree on the entry criteria and on the rationale, that the great majority of known vulnerabilities are never exploited, so patch prioritisation by evidence of exploitation is more efficient than prioritisation by severity score alone. The catalogue page, retrieved on 16 September 2026, is a living document rather than a fixed record, and this description reflects its content as of that date; CISA notes the directive itself has since been superseded by a later one, a change this article records but does not evaluate.

Why it mattered

The directive reframed the basic question a defender asks about a new vulnerability, from how severe could this be to is this actually being used against anyone right now, and made the second question the trigger for a mandatory deadline rather than a discretionary judgment call. CVSS severity scores describe technical impact if exploited, not the likelihood that a given vulnerability will be the one attackers actually choose, and CISA's own catalogue criteria point out that a small fraction of known vulnerabilities are ever weaponised. The catalogue itself, updated as new evidence arrives, became a reference point cited well beyond the federal agencies it directly binds, including by private-sector vulnerability management programmes.

Defensive takeaway

Check the Known Exploited Vulnerabilities catalogue against your own asset inventory on a recurring basis, and treat a listing there as a harder deadline than a high severity score alone would justify, since the catalogue is evidence of real use, not a theoretical rating.

  • Do you cross-reference your patch backlog against the catalogue, or rely on severity scores alone to prioritise?
  • How quickly could you identify every instance of a newly catalogued vulnerability across your environment?
  • What does the catalogue not tell you about vulnerabilities in software you use that has not yet drawn attacker attention?

A catalogue built on confirmed exploitation is a better patch-priority signal than severity alone, but it is necessarily a lagging one, since a vulnerability only qualifies after someone has already used it against a real target.

Defensive takeaway

Cross-reference your patch backlog against the Known Exploited Vulnerabilities catalogue on a recurring basis, and treat a listing there as a harder deadline than a high severity score alone would justify.

The directive's own text and CISA's current catalogue page agree on the entry criteria and remediation timelines. The catalogue is a living document, described here as retrieved on 16 September 2026; the directive itself has since been superseded, a change this article records but does not evaluate.

Sources & reading trail

BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities ↗

The directive's required agency actions, remediation timelines, and CISA's criteria for adding a vulnerability to the catalogue.

government-primary · Source published: 3 November 2021 · Retrieved: 16 September 2026

Known Exploited Vulnerabilities Catalog ↗

Describes how the catalogue is populated and used today, and states it covers only vulnerabilities with confirmed active exploitation.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.