HomeSecurityCISA withdraws 10 Emergency Directives

CISA withdraws 10 Emergency Directives

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the withdrawal of 10 Emergency Directives issued between 2019 and 2024, stating that the required actions have been completed or are now covered by Binding Operational Directive 22-01. CISA noted that this is the largest number of Emergency Directives it has closed at one time. “By law, CISA issues Emergency Directives to rapidly mitigate emerging threats and minimize the impact by limiting the directives to the shortest possible time,” it explains.

See also: CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

CISA Emergency Directives

“After a comprehensive review of all active directives, CISA has determined that the required actions have been successfully implemented or are now covered through Binding Operating Directive (BOD) 22-01, Mitigating the Significant Risk from Known Exploited Vulnerabilities.” Binding Operating Directive 22-01 uses the agency’s list of Known Exploited Vulnerabilities (KEV) to notify federal civil agencies of actively exploited vulnerabilities and when systems should be patched for them.

Emergency Directives are intended to address immediate risks and remain in effect only as long as necessary. The full list of Emergency Directives that have been closed is:

– ED 19-01: Mitigating DNS Infrastructure Spoofing

– ED 20-02: Windows Vulnerability Mitigation from Patch Tuesday January 2020

– ED 20-03: Windows DNS Server Vulnerability Mitigation from Patch Tuesday July 2020

– ED 20-04: Netlogon Elevation of Privilege Vulnerability Mitigation from Patch Tuesday August 2020

See also: CISA added Sierra Wireless Routers vulnerability to KEV List

CISA withdraws 10 Emergency Directives

– ED 21-01: SolarWinds Orion Code Violation Mitigation

– ED 21-02: Mitigating Microsoft Exchange On-Premises Product Vulnerabilities

– ED 21-03: Pulse Connect Secure Product Vulnerability Mitigation

– ED 21-04: Windows Print Spooler Service Vulnerability Mitigation

– ED 22-03: VMware Vulnerability Mitigation

– ED 24-02: Mitigating the Significant Risk of a Government Breach of Microsoft Email System

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Many of these directives addressed vulnerabilities that were quickly exploited and are now part of the CISA KEV list.

Under BOD 22-01, federal civil agencies are required to patch vulnerabilities listed on the CVE list by specific dates set by CISA. By default, agencies have up to six months to patch vulnerabilities assigned to CVEs prior to 2021, with newer vulnerabilities patched within two weeks. However, CISA may set significantly shorter patch timelines when deemed high risk.

See also: CISA added OSGeo GeoServer vulnerability to KEV Catalog

CISA withdraws 10 Emergency Directives

In a recent example, services were required to patch Cisco devices affected by the actively exploited vulnerabilities CVE-2025-20333 and CVE-2025-20362 within one day.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS