The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new binding operational directive requiring federal agencies to identify and remove network edge devices that no longer receive security updates from manufacturers. It also warned that end-of-life edge devices (including routers, firewalls, and network switches) leave federal systems vulnerable to newly discovered exploits and expose them to "disproportionate and unacceptable risks." "The imminent threat of exploitation to agency information systems running EOS edge devices is substantial and constant, resulting in a significant threat to federal property. CISA is aware of widespread exploitation campaigns by advanced threat actors targeting EOS edge devices," the cybersecurity agency said on Thursday. "These devices are especially vulnerable to cyber exploits targeting newly discovered, unpatched vulnerabilities. Additionally, they no longer receive supported updates from the original equipment manufacturer, exposing federal systems to disproportionate and unacceptable risks." Binding Operational Directive 26-02 (BOD 26-02) mandates U.S. government agencies to decommission end-of-support (EOS) hardware and software on federal networks to prevent exploitation by advanced threat actors. The directive requires immediate action on vendor-supported devices running end-of-support software for which updates are available, and an inventory of all devices on CISA's end-of-support list within three months. ...
CISA orders federal agencies to replace end-of-life edge devices
BleepingComputer
·Sergiu Gatlan
·Published Feb 6, 2026
·Updated
Affected Software
1 affected component
CISA Edge Devices>end-of-support
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's directive for federal agencies to replace end-of-life network edge devices that no longer receive security updates.
2
What security implications are discussed?
The article highlights the risks associated with outdated edge devices, including vulnerabilities from lack of security updates.
3
What products or software are affected?
The affected products include edge devices that have reached their end-of-support status and do not receive manufacturer updates.
4
Who is affected by the CISA directive?
The CISA directive primarily affects federal agencies in the United States responsible for cybersecurity.
5
What actions must federal agencies take according to the directive?
Federal agencies must identify and remove their end-of-life edge devices to enhance their network security posture.