The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01. CISA said this is the largest number of Emergency Directives it has closed at one time. "By statute, CISA issues Emergency Directives to rapidly mitigate emerging threats and to minimize the impact by limiting directives to the shortest time possible," explains CISA. "Following a comprehensive review of all active directives, CISA determined that required actions have been successfully implemented or are now encompassed through Binding Operational Directive (BOD) 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities. " Binding Operational Directive 22-01 uses the agency's Known Exploited Vulnerabilities (KEV) catalog to alert federal civilian agencies of actively exploited flaws and when systems must be patched against them. Emergency Directives are meant to address urgent risks and remain in place only as long as needed. The complete list of Emergency Directives closed today is: Many of those directives addressed vulnerabilities that were exploited quickly and are now part of CISA's KEV catalog. Under BOD 22-01, federal civilian agencies are required to patch vulnerabilities listed in the KEV catalog by specific dates set by CISA. By default, agencies have up to six months to fix flaws assigned to CVEs before 2021, wi...
CISA retires 10 emergency cyber orders in rare bulk closure
BleepingComputer
·Lawrence Abrams
·Published Jan 9, 2026
·Updated
Affected Software
2 affected components
Cisco devices=CVE-2025-20333
Cisco devices=CVE-2025-20362
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's retirement of 10 Emergency Cyber Directives due to completed actions or updates under Binding Operational Directive 22.
2
What reasons did CISA give for retiring the emergency cyber orders?
CISA stated that the required actions from these orders have been completed or are now encompassed by new directives.
3
Which specific products are mentioned as affected in the article?
The article mentions Cisco devices that are associated with vulnerabilities CVE-2025-20333 and CVE-2025-20362.
4
What time frame do the retired Emergency Directives cover?
The retired Emergency Directives were issued between 2019 and 2024.
5
What is the significance of binding operational directive 22 mentioned in the article?
Binding Operational Directive 22 consolidates and governs actions previously covered by the now-retired Emergency Directives.