CERT-In 12-hour KEV remediation guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response time for exposed Indian organizations. The guidance pairs that timeline with risk-based deadlines for other exposed and high-value flaws and points defenders toward the KEV catalog and EPSS for prioritization. When no patch is available, it calls for interim controls such as isolation, access restriction, or WAF protection until remediation lands.
Related Happenings
Pentagon suspends CMMC phase two for 60-day review
Public Sector Action
H score24
First: 14.07.2026 09:37
Last: 14.07.2026 09:37
Sources 1
About this happening:
The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
Pentagon suspends CMMC phase two for 60-day review
Public Sector ActionAbout this happening: The Pentagon suspended CMMC phase two and opened a 60-day review, delaying new certification requirements for defense contractors and subcontractors. The pause...
CISA BOD 26-04 three-day remediation directive
Public Sector Action
H score36
First: 24.06.2026 17:35
Last: 24.06.2026 17:35
Sources 1
About this happening:
CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA BOD 26-04 three-day remediation directive
Public Sector ActionAbout this happening: CISA's BOD 26-04 requires federal agencies to apply available security updates or vendor-recommended mitigations within three days, accelerating remediation for acti...
CISA KEV update and FCEB remediation deadline
Public Sector Action
H score33
First: 10.06.2026 17:44
Last: 10.06.2026 17:44
Sources 1
About this happening:
CISA added three actively exploited vulnerabilities to the KEV catalog and ordered Federal Civilian Executive Branch agencies to remediate by June 23, 2026. Th...
CISA KEV update and FCEB remediation deadline
Public Sector ActionAbout this happening: CISA added three actively exploited vulnerabilities to the KEV catalog and ordered Federal Civilian Executive Branch agencies to remediate by June 23, 2026. Th...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector Action
H score38
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
How related:
Organizations in India have been urged to patch actively exploited internet-facing vulnerabilities within 12 hours under new guidance that responds to the speed AI now brings to cyber-attacks.
About this happening:
CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
CERT-In issues 12-hour patch guidance for Indian organizations
Public Sector ActionHow related: Organizations in India have been urged to patch actively exploited internet-facing vulnerabilities within 12 hours under new guidance that responds to the speed AI now brings to cyber-attacks.
About this happening: CERT-In published new guidance on May 25 urging Indian organizations to patch actively exploited internet-facing vulnerabilities within 12 hours, tightening respon...
CERT-In issues rapid patching guidelines for internet-facing systems
Public Sector Action
H score38
First: 26.05.2026 12:13
Last: 26.05.2026 12:13
Sources 1
About this happening:
CERT-In issued new guidelines requiring organizations to patch internet-exposed critical vulnerabilities within 12 hours where feasible, tightening defensive timel...
CERT-In issues rapid patching guidelines for internet-facing systems
Public Sector ActionAbout this happening: CERT-In issued new guidelines requiring organizations to patch internet-exposed critical vulnerabilities within 12 hours where feasible, tightening defensive timel...
Timeline
-
26.05.2026 13:30 2 articles · 1mo ago
CERT-In sets 12-hour remediation deadline for exposed KEVs
Mitigation Patch UpdateCERT-In published guidance on May 25 for organizations in India that sets an indicative 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, with staged timelines for other risk tiers and interim isolation, access restriction, or web application firewall protection when no patch exists. The guidance also points organizations toward the KEV catalog and EPSS for prioritization and reiterates the six-hour cyber-incident reporting requirement.
Show sources
- India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws — www.infosecurity-magazine.com — 26.05.2026 13:30
- India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws — www.infosecurity-magazine.com — 26.05.2026 13:30