• News/
  • https://www.bleepingcomputer.com/news/security/cisa-retires-10-emergency-cyber-orders-in-rare-bulk-closure/

CISA retires 10 emergency cyber orders in rare bulk closure

BleepingComputer
·
Lawrence Abrams
·
Published Jan 9, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01. CISA said this is the largest number of Emergency Directives it has closed at one time. "By statute, CISA issues Emergency Directives to rapidly mitigate emerging threats and to minimize the impact by limiting directives to the shortest time possible," explains CISA. "Following a comprehensive review of all active directives, CISA determined that required actions have been successfully implemented or are now encompassed through Binding Operational Directive (BOD) 22-01, Reducing the Significant Risk of Known Exploited Vulnerabilities. " Binding Operational Directive 22-01 uses the agency's Known Exploited Vulnerabilities (KEV) catalog to alert federal civilian agencies of actively exploited flaws and when systems must be patched against them. Emergency Directives are meant to address urgent risks and remain in place only as long as needed. The complete list of Emergency Directives closed today is: Many of those directives addressed vulnerabilities that were exploited quickly and are now part of CISA's KEV catalog. Under BOD 22-01, federal civilian agencies are required to patch vulnerabilities listed in the KEV catalog by specific dates set by CISA. By default, agencies have up to six months to fix flaws assigned to CVEs before 2021, wi...

Read full article

Affected Software

2 affected components
Cisco devices=CVE-2025-20333
Cisco devices=CVE-2025-20362

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's retirement of 10 Emergency Cyber Directives due to completed actions or updates under Binding Operational Directive 22.

2

What reasons did CISA give for retiring the emergency cyber orders?

CISA stated that the required actions from these orders have been completed or are now encompassed by new directives.

3

Which specific products are mentioned as affected in the article?

The article mentions Cisco devices that are associated with vulnerabilities CVE-2025-20333 and CVE-2025-20362.

4

What time frame do the retired Emergency Directives cover?

The retired Emergency Directives were issued between 2019 and 2024.

5

What is the significance of binding operational directive 22 mentioned in the article?

Binding Operational Directive 22 consolidates and governs actions previously covered by the now-retired Emergency Directives.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203