Vulnerability intelligence
CVE-2026-35273 — Security Advisory
Binding Operational Directive 26-04 replaces the old 30-day patch window with risk-based timelines. Publicly exposed, auto-exploitable vulnerabilities in the KEV catalog get a 3-day deadline. The directive cites AI-accelerated exploitation as the reason. WordPress sites with 18,005 CVEs just became a compliance crisis.
CVSS 9.8
2026
What WebPulse reported · 2 analyses
CISA BOD 26-04 Replaces BOD 19-02: 3 Days to Patch Critical Vulnerabilities
Binding Operational Directive 26-04 replaces the old 30-day patch window with risk-based timelines. Publicly exposed, auto-exploitable vulnerabilities in the KE
June 16, 2026
ShinyHunters Claims 297 GB From the Council of Europe. Payroll Records for 10,000 Employees. Medical Data. Tax Numbers. Deadline: June 16.
429,000 files allegedly exfiltrated from HR, the Parliamentary Assembly, the Secretariat, and the European Directorate for Quality of Medicines. The Council of
June 15, 2026
Related vulnerabilities