Security/ security · cisa · federal · ai

CISA Cuts Patch Window to 3 Days for Some Federal Bugs

AI tools are compressing the gap between vulnerability disclosure and working exploit, and CISA is adjusting its patch timelines to match.

CISA Cuts Patch Window to 3 Days for Some Federal Bugs

Federal agencies have a new patch deadline: as little as three days for some security vulnerabilities, under updated CISA guidance driven by AI-assisted attacks.

CISA updated its directive requirements for federal civilian agencies, compressing the time some agencies have to remediate known exploited vulnerabilities down to three days. The move is a direct response to AI tools that have dramatically shortened the window between vulnerability disclosure and active exploitation. "Defenders cannot afford to take weeks to patch," a CISA official said Wednesday.

The change reflects a genuine shift in threat tempo. AI tools — available to both defenders and attackers — have reduced exploit development from a weeks-long craft to something that can happen in hours. A three-day window sounds aggressive; against an AI-assisted adversary who has been working the same bug since disclosure day one, it may just be catching up.

Whether agencies can actually hit that deadline is another matter. Federal IT environments tend to be sprawling, legacy-heavy, and slow to update — the same structural problems that have long made patch deadlines more aspirational than operational. CISA can set the clock; clearing the backlog is a different problem.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →