Topic

CISA Guidance and Directives

Reference hub on CISA directives, the KEV catalog, and the Zero Trust Maturity Model 2.0, read for what each implies about enforcement placement.

14 posts

CISA, the Cybersecurity and Infrastructure Security Agency, is the United States civilian cyber defense agency. It maintains the Known Exploited Vulnerabilities (KEV) catalog, issues binding operational directives to federal civilian agencies, and publishes zero trust and secure by design guidance that is used well beyond government.

Teams treat KEV as a patch queue and stop there. The pattern in the catalog says something else: the exploited product is frequently the control that was supposed to be the trust boundary, including VPN concentrators, file transfer appliances, network controllers, and endpoint agents. When that component falls, every protection layered behind it inherits the failure.

Posts under this hub read individual KEV entries for what they imply about enforcement placement, and work through the CISA Zero Trust Maturity Model 2.0, its Data pillar in particular, along with CISA guidance on operational technology and secure by design commitments. The Data pillar is the one where architecture, not procurement, decides the maturity stage.

Frequently asked questions

What is the CISA KEV catalog?

The Known Exploited Vulnerabilities catalog is the CISA list of vulnerabilities with confirmed active exploitation. Binding Operational Directive 22-01 requires federal civilian executive branch agencies to remediate listed vulnerabilities by the due date CISA assigns. Other organizations use it voluntarily as a prioritization signal, since entries reflect observed attacks rather than theoretical severity scores.

What are the pillars of the CISA Zero Trust Maturity Model?

The CISA Zero Trust Maturity Model 2.0 defines five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. Three capabilities cut across all five: visibility and analytics, automation and orchestration, and governance. Each pillar is assessed against four maturity stages, running from Traditional through Initial and Advanced to Optimal.

Is patching a KEV vulnerability enough?

Patching closes one vulnerability. It does not change what an attacker reaches if the compromised component was the only thing standing between them and readable data. When a file transfer appliance or VPN concentrator is the trust boundary, its compromise exposes everything behind it, so the durable change moves enforcement onto the data object itself.

What does CISA Secure by Design ask software vendors to do?

Secure by Design asks vendors to own customer security outcomes rather than shipping hardening guidance and leaving the work to buyers. Its voluntary pledge sets goals covering multifactor authentication, elimination of default passwords, reduction of whole vulnerability classes, timely patching, vulnerability disclosure policies, and accurate CVE records. Signatories commit to showing measurable progress publicly.

Reading on cisa guidance and directives

Lattix branded cover for Check Point VPN CVE-2026-50751. /42 section number, June 2026 KEV disclosure date, CVSS 9.3 authentication-bypass statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level policy enforcement point in a VPN-to-data flow strip.

Check Point VPN CVE-2026-50751 Is in KEV. The Concentrator Is Not the Trust Boundary.

July 6, 2026

Check Point VPN CVE-2026-50751 is an actively exploited IKEv1 authentication bypass that grants an unauthenticated attacker a valid VPN session. CISA added it to KEV with a June 11, 2026 federal deadline. A VPN session is network reachability, not authority over data.

Read More →
Lattix branded cover for PTC Windchill CVE-2026-12569. /43 section number, June 2026 KEV disclosure date, CVSS 9.3 unauthenticated-RCE statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level policy enforcement point in a repository-to-data flow strip.

PTC Windchill CVE-2026-12569 Is in KEV. The PLM Repository Is the Trust Boundary.

July 6, 2026

PTC Windchill CVE-2026-12569 is an actively exploited, unauthenticated RCE that lets attackers drop web shells on the system holding a manufacturer's engineering IP. CISA added it to KEV with a June 28, 2026 deadline. When the repository is the trust boundary, the data has none.

Read More →
Lattix branded cover for CISA Secure by Design AI Pledge One Year In. /30 section number, 2024 pledge launch date, signatory commitment categories statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the evidence pillar in a pledge commitment strip.

CISA Secure by Design AI Pledge: A Year In, Evidence Is What Is Missing

June 23, 2026

The CISA Secure by Design AI pledge launched in 2024 with broad industry signatories. A year later, evidence supporting the pledge commitments remains uneven. Data provenance, training-set lineage, and access governance over model outputs are the evidence categories vendors cannot produce.

Read More →
Lattix branded cover for Chromium V8 CVE-2026-11645. /39 section number, June 2026 KEV disclosure date, CVSS 8.8 out-of-bounds renderer statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level PEP in a browser-to-data flow strip.

Chromium V8 CVE-2026-11645 Is in KEV. The Browser Is an Endpoint Data Surface.

June 22, 2026

Chromium V8 CVE-2026-11645 is an actively exploited out-of-bounds flaw giving an attacker read and write access inside the renderer. CISA added it to KEV with a June 23, 2026 federal deadline. The browser is where enterprise data is read, and the renderer holds the cleartext.

Read More →
Lattix branded cover for Arista EOS CVE-2026-7473. /40 section number, June 2026 KEV disclosure date, CVSS 6.9 no-patch statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level PEP in a network-fabric-to-data flow strip.

Arista EOS CVE-2026-7473 Forwards Untrusted Tunnel Traffic. The Fabric Is Not the Boundary.

June 19, 2026

Arista EOS CVE-2026-7473 is an actively exploited tunnel decapsulation flaw that makes a switch forward attacker traffic into isolated segments. CISA added it to KEV with a June 23, 2026 federal deadline, and Arista will not patch it.

Read More →
Lattix branded cover for SolarWinds Serv-U CVE-2026-28318. /38 section number, June 2026 KEV disclosure date, 12,000+ exposed-hosts statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level PEP in a transfer-to-data flow strip.

SolarWinds Serv-U CVE-2026-28318 Is in KEV. The File Transfer Appliance Is the Trust Boundary.

June 13, 2026

SolarWinds Serv-U CVE-2026-28318 is an actively exploited, unauthenticated flaw that crashes the file transfer service. CISA added it to KEV with a June 19, 2026 federal deadline. Managed file transfer keeps proving the appliance is a transport, not a trust boundary.

Read More →
Lattix branded cover for Microsoft Defender CVE-2026-41091 Escalates to SYSTEM. /37 section number, May 2026 zero-day disclosure date, CVSS 7.8 local-to-SYSTEM statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the data-layer PEP in a host-to-data flow strip.

Microsoft Defender CVE-2026-41091 Escalates to SYSTEM. The Endpoint Control Is the Attack Surface.

June 11, 2026

Microsoft Defender CVE-2026-41091 is an actively exploited link-following flaw that elevates a local user to SYSTEM. CISA added it to KEV with a June 3, 2026 federal deadline. When the security tool is the escalation path, object-level enforcement is what survives.

Read More →
Lattix branded cover for Cisco SD-WAN CVE-2026-20182 Bypasses the Network Controller. /24 section number, May 2026 zero-day disclosure date, unauthenticated admin bypass statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the data-layer boundary in a controller-to-data flow strip.

Cisco SD-WAN CVE-2026-20182 Bypasses the Network Controller. The Data Layer Holds.

June 2, 2026

Cisco confirmed CVE-2026-20182 against Catalyst SD-WAN Controller as exploited in the wild in May 2026. Unauthenticated attackers gain admin on affected systems. CISA added the flaw to KEV. SD-WAN is the East-West choke point that perimeter zero trust depends on. Data-level enforcement does not.

Read More →
Lattix branded cover for Langflow CVE-2025-34291 Hands Over the AI Orchestrator's Credential Stash. /25 section number, May 21 2026 KEV addition and June 4 2026 FCEB deadline, CVSS 9.4 statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the policy enforcement point in an LLM provider credential release flow strip.

Langflow CVE-2025-34291 Hands Over the AI Orchestrator's Credential Stash

June 2, 2026

CISA added Langflow CVE-2025-34291 to KEV on May 21, 2026 with a June 4 FCEB deadline. The CVSS 9.4 flaw turns a visit to a malicious page into account takeover plus RCE on a Langflow workspace. The harvested material is the operator's full AI credential stash.

Read More →
Lattix branded cover for The Linux Copy Fail CVE-2026-31431 Reaches Root. /23 section number, May 1 2026 KEV add date, 732-byte exploit statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the data-layer boundary in a kernel-to-data flow strip.

The Linux Copy Fail CVE-2026-31431 Reaches Root. Object-Level Enforcement Reaches the Data.

May 28, 2026

CVE-2026-31431 escalates an unprivileged Linux user to root with a 732-byte Python script. CISA added it to KEV May 1 with a federal remediation deadline of May 15. Patching closes the vector. Object-level cryptographic enforcement closes the consequence.

Read More →
Lattix branded cover for CISA's PQC product categories and federal acquisition. /11 section number, January 23 2026 publication date, two-tier procurement category map, IBM Plex Mono on dark grid background, surgical yellow accent.

CISA's PQC Product Categories Move Quantum-Safe From Roadmap to Procurement

May 12, 2026

CISA's January 23, 2026 product categories list, issued under Executive Order 14306, defines where federal buyers should acquire only PQC-capable products. The list is advisory. The procurement language built on it will not be.

Read More →
Lattix branded cover for Federal Zero Trust Deadlines Are Binding. Data Layer Enforcement Is Not. Yellow accent bar, /02 section number, IBM Plex Mono typography on dark grid background.

Federal Zero Trust Deadlines Are Binding. Data Layer Enforcement Is Not.

May 6, 2026

CISA's April 2026 binding directive sets Q3/Q4 2026 deadlines for identity, network, and device zero trust controls. The data layer remains optional. Programs that hit every milestone without object-level enforcement still fail on a compromised service account.

Read More →
Lattix branded cover for CISA's April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed. /04 section number, OT zero trust maturity reference, IBM Plex Mono on dark grid background, surgical yellow accent.

CISA's April 2026 OT Zero Trust Guidance Leaves the Data Plane Unaddressed

May 5, 2026

On April 30, 2026, CISA and four federal partners released a joint guide adapting zero trust principles to operational technology. The guide advances identity, network, and visibility maturity for OT. The data plane remains an open enforcement gap.

Read More →
Diagram showing the disclosure surface around a patched SharePoint instance: the patch closes the network vector while the pre-patch read and write events remain cryptographically unaccounted for without data-layer enforcement.

SharePoint CVE-2026-32201 Is in KEV. The Disclosure Surface Is the Real Issue.

April 22, 2026

CISA added the April SharePoint spoofing zero-day to KEV on April 14 with an FCEB remediation deadline of April 28. Patching closes the vector. It does not answer what an attacker read, modified, or signed before the update landed.

Read More →