CISA Directives
cisa-directives · A · active
https://www.cisa.gov/news-events/directives
Binding Operational Directives and Emergency Directives — high-priority defender signal. WebFetch HTTP 403 (re-confirmed 2026-05-08). REQUIRED: `python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives`. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge: python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives to discover /news-events/directives/{slug} hrefs, then `cisa page <full URL>` per directive for the body.. AVOID: WebFetch 403s the CISA UA — skip it, go straight to the bridge `cisa page` subcommand.. | 2026-07-04: bridge (cisa page) upstream HTTP 403 again — consecutive_fetch_failures 2; 403 is transport blocking (does NOT demote per lifecycle rules). CISA KEV JSON API still works via the bridge. | 2026-07-05 root-cause confirmed: www.cisa.gov dynamic paths (/news-events/*, all .xml feeds, and the CSAF .well-known) are blocked by Akamai bot management (`Access Denied`, `Reference #18.*`) for EVERY UA/header combination tested (chrome/firefox/googlebot/curl/minimal/+Referer all 403) — the block keys off the egress TLS/behavioural fingerprint, so it is unfixable from request headers. Only the STATIC /sites/default/files/feeds/ path (KEV JSON) is served. No reachable alternative for the advisory HTML content (search.gov results are a JS shell needing an API key; Wayback has no snapshots). SUBSTITUTE: `cisa-kev` JSON API for exploited-vuln ground truth + WebSearch corroboration for advisory narrative (covered_anyway). STAYS ACTIVE — a 403 is a transport block and NEVER demotes (hard rule). source_health.py now classifies this `bridge-blocked` (handled), not `needs-demote`, so the routine stops re-flagging it every run. | 2026-07-05 RECOVERED — CISA dynamic content is now reachable. The Akamai 403 on every UA still holds for a DIRECT fetch, but `tools/fetch_source.py` routes cisa.gov through the r.jina.ai reader proxy (server-side fetch, bypasses the Akamai fingerprint) for `cisa page` / `cisa feed`, and through the cisagov/CSAF GitHub mirror (raw.githubusercontent.com, not proxy-blocked) for `cisa csaf-recent` / `cisa csaf` (fully-structured ICS advisories). This SUPERSEDES the earlier KEV+WebSearch-substitute handling — the advisory/directive/news content itself is now fetchable with full detail. `cisa-kev` JSON remains the exploited-vuln ground truth. FETCH now works: `python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives` (reader-proxy, full body) to read BOD/ED text; the filtered listing `.../directives/all?f[0]=directive_type:35` works via `cisa page` too. | 2026-07-05 admiralty audit: A (primary-authority) — CISA directives; bridge 403 is a known transport block (no demotion), directive series confirmed current via KEV references. Status stays active. | 2026-07-09: no RSS feed exists for directives; the listing DOES hydrate through the reader — `cisa page https://www.cisa.gov/news-events/directives` then grep /news-events/directives/<slug> hrefs for discovery (confirmed 2026-07-09: returns current BOD/ED links); new directives are also announced in the cisa-news feed (news.xml).
Cited in 6 entries
Citation cadence
Citation days per ISO week (5 weeks of coverage span, total 4).
- CISA replaces the flat KEV 14-day rule with risk-tiered remediation (BOD 26-04)2026-06-14
- CISA replaces the KEV 14-day rule: BOD 26-04 introduces risk-tiered remediation with a 3-day class for the worst exposures2026-06-12
- CVE-2026-20182 — Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeover2026-05-15
- Cisco Catalyst SD-WAN: CVE-2026-20182 Authentication Bypass and UAT-8616 Kill Chain2026-05-15
- Cisco Catalyst SD-WAN CVE-2026-20182 — UAT-8616 active, CISA Emergency Directive ED-26-03, 10+ companion-CVE clusters2026-05-11
- CISA Emergency Directive ED-26-03 — Cisco Catalyst SD-WAN2026-05-11