CISA Directives
cisa-directives · A · active
https://www.cisa.gov/news-events/directives
Binding Operational Directives and Emergency Directives, high-priority defender signal. WebFetch HTTP 403 (re-confirmed 2026-05-08). REQUIRED: `python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives`. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge: python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives to discover /news-events/directives/{slug} hrefs, then `cisa page <full URL>` per directive for the body.. AVOID: WebFetch 403s the CISA UA, skip it, go straight to the bridge `cisa page` subcommand.. | 2026-07-04: bridge (cisa page) upstream HTTP 403 again, consecutive_fetch_failures 2; 403 is transport blocking (does NOT demote per lifecycle rules). CISA KEV JSON API still works via the bridge. | 2026-07-05 root-cause confirmed: www.cisa.gov dynamic paths (/news-events/*, all .xml feeds, and the CSAF .well-known) are blocked by Akamai bot management (`Access Denied`, `Reference #18.*`) for EVERY UA/header combination tested (chrome/firefox/googlebot/curl/minimal/+Referer all 403), the block keys off the egress TLS/behavioural fingerprint, so it is unfixable from request headers. Only the STATIC /sites/default/files/feeds/ path (KEV JSON) is served. No reachable alternative for the advisory HTML content (search.gov results are a JS shell needing an API key; Wayback has no snapshots). SUBSTITUTE: `cisa-kev` JSON API for exploited-vuln ground truth + WebSearch corroboration for advisory narrative (covered_anyway). STAYS ACTIVE; a 403 is a transport block and NEVER demotes (hard rule). source_health.py now classifies this `bridge-blocked` (handled), not `needs-demote`, so the routine stops re-flagging it every run. | 2026-07-05 RECOVERED; CISA dynamic content is now reachable. The Akamai 403 on every UA still holds for a DIRECT fetch, but `tools/fetch_source.py` routes cisa.gov through the r.jina.ai reader proxy (server-side fetch, bypasses the Akamai fingerprint) for `cisa page` / `cisa feed`, and through the cisagov/CSAF GitHub mirror (raw.githubusercontent.com, not proxy-blocked) for `cisa csaf-recent` / `cisa csaf` (fully-structured ICS advisories). This SUPERSEDES the earlier KEV+WebSearch-substitute handling; the advisory/directive/news content itself is now fetchable with full detail. `cisa-kev` JSON remains the exploited-vuln ground truth. FETCH now works: `python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives` (reader-proxy, full body) to read BOD/ED text; the filtered listing `.../directives/all?f[0]=directive_type:35` works via `cisa page` too. | 2026-07-05 admiralty audit: A (primary-authority), CISA directives; bridge 403 is a known transport block (no demotion), directive series confirmed current via KEV references. Status stays active. | 2026-07-09: no RSS feed exists for directives; the listing DOES hydrate through the reader, `cisa page https://www.cisa.gov/news-events/directives` then grep /news-events/directives/<slug> hrefs for discovery (confirmed 2026-07-09: returns current BOD/ED links); new directives are also announced in the cisa-news feed (news.xml). | 2026-07-25: S1 reported no `cisa-directives` bridge subcommand in fetch_source.py; content reachable via `cisa page <advisory-url>`. fetch_method kept as-is pending a recipe; not demoted (403/tooling-gap, not source death). | 2026-08-04 run: RECIPE CONFIRMED, `python3 tools/fetch_source.py cisa page https://www.cisa.gov/news-events/directives` works and returns the full ED/BOD listing with drillable per-directive URLs. Caveat: the listing carries no per-item publish dates, so recency must come from the drilled directive page. Newest substantive item BOD 26-04 (2026-06-10), out of window. | 2026-08-16: unreachable this run for the same reason as cisa-advisories (direct 403 + reader pool exhausted). NOT demoted. No evidence a new directive published in-window. | 2026-08-17: unreachable again, direct transport refused and the jina reader pool returned HTTP 402 on every rotating key, so the documented ladder had no last rung. Transport blocking plus an exhausted reader quota; NOT demoted. | 2026-08-18: same cisa.gov condition, fourth consecutive run; rotation-priority source. NOT demoted. No evidence from any other source that a directive published in-window. | 2026-08-19: fifth consecutive unreachable run, same cisa.gov condition; rotation-priority source, NOT demoted. | 2026-09-07: S2 confirms the bridge/jina fetch of the directives listing still returns only the site's filter-facet JS shell (6th+ consecutive occurrence per prior notes) -- a recipe gap (no structured CISA directives feed/API identified yet), not an anti-bot block; not demoted, needs a recipe fix on a future run. | 2026-09-13 intel run (S1/S2): bridge/jina still return only the JS filter-facet shell; recipe gap persists, not demoted (403/anti-bot-shaped block, never demotes).
Cited in 3 entries
Citation cadence
Citation days per ISO week (5 weeks of coverage span, total 2).
- CISA replaces the KEV 14-day rule: BOD 26-04 introduces risk-tiered remediation with a 3-day class for the worst exposures2026-06-12
- CVE-2026-20182, Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeover2026-05-15
- Cisco Catalyst SD-WAN: CVE-2026-20182 Authentication Bypass and UAT-8616 Kill Chain2026-05-15