palmiq Speak to an expert

CISA BOD 26-04 Edge Device Inventory: An SMB Guide

7 min read

A plain guide to CISA BOD 26-04, edge device inventory, and the FortiOS KEV entry — what applies to an SMB, and what doesn't.

Business professionals in a meeting with laptops and notebooks, discussing strategy.

The phrase “CISA BOD 26-04 edge device inventory” is turning up in a lot of security conversations lately, and it needs a caveat up front: the directive says nothing about edge devices, and it does not bind your business. It binds federal civilian agencies.

It still matters to you, because the vulnerability that best illustrates the directive’s logic landed on a product plenty of small businesses run at the edge of their network: FortiOS.

Here’s the part worth your attention. The hard problem in a three-day remediation window is not patching. It’s knowing, on day one, which devices you own, which are reachable from the internet, what firmware they run, and whether the vendor still supports them. For an SMB with a mixed estate accumulated over a decade, that list usually doesn’t exist in one place.

What is CISA BOD 26-04, and who does it apply to?

CISA issued Binding Operational Directive 26-04, “Prioritizing Security Updates Based on Risk,” on June 10, 2026. Per CISA’s announcement, it requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities while explicitly allowing lower-risk ones to be deferred — a move away from patching everything on a severity clock.

FedRAMP’s notice on the directive describes the prioritization model as four factors: public exposure, Known Exploited Vulnerabilities (KEV) status, automatability, and technical impact. Cloud Security Alliance analysts note that BOD 26-04 replaces BOD 19-02 and BOD 22-01, and describe it as the first concrete enforcement action stemming from Section 2(c) of Executive Order 14409. Because BOD 22-01 created the KEV catalog obligation, the practical effect is a change in how KEV is consumed, not its retirement.

One more piece of framing, straight from CISA: the agency’s own announcement points to AI potentially narrowing the window between a patch release and defender reaction time. That’s CISA’s characterization, and it’s worth taking at face value without embellishing it.

It’s not an edge-device directive, by the way. Nothing in its title or scope singles out firewalls. The edge connection is analytical: edge devices are the asset class most likely to hit all four criteria at once, because they’re publicly exposed by design and often grant broad control when compromised.

Does BOD 26-04 apply to private companies and small businesses?

No. BOD 26-04 binds Federal Civilian Executive Branch agencies. It does not legally bind an SMB, a nonprofit, a private medical practice or a school district. Anyone telling you that you “must comply” is wrong.

You may still be measured against it. FedRAMP responded within weeks, saying it would align its Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules to the directive — a sign that BOD 26-04 propagates into the commercial supply chain, not just agency networks. If you sell to the federal government, subcontract to a prime, or renew a cyber policy, expect KEV-driven remediation timelines to show up as a contractual flow-down or an underwriting expectation.

If you’re on a CMMC or NIST 800-171 path, be precise here too: BOD 26-04 is not a CMMC requirement. The directional point is that disciplined, KEV-driven remediation supports the flaw remediation and risk assessment practices you’re already assessed on.

What is CVE-2025-68686 in FortiOS?

CVE-2025-68686 is a Fortinet FortiOS “exposure of sensitive information to an unauthorized actor” vulnerability that CISA added to the KEV catalog based on evidence of active exploitation, alongside CVE-2026-16812 affecting Arista VeloCloud Orchestrator On-Prem. Coverage from Cyber Security News dated July 28, 2026 maps the flaw to CWE-200 and notes that FortiOS is the operating system used across FortiGate firewalls and other Fortinet products.

Before you act on version numbers, pull the affected release ranges, fixed builds and the exact KEV date-added and due-date from Fortinet’s PSIRT advisory and the CISA KEV catalog directly. Those details change, and getting them from a blog post — including this one — is how the wrong branch gets patched.

The more useful observation is that this isn’t a one-off. Fortinet products, including but not limited to its edge platforms, have appeared in KEV repeatedly:

  • CVE-2024-23113 — a flaw in the FortiOS fgfmd daemon allowing a remote unauthenticated attacker to run arbitrary code, with a CVSS 3.1 score of 9.8 and a KEV listing, per Quorum Cyber’s KEV summary.
  • CVE-2025-59718 and CVE-2025-59719 — two critical authentication bypass flaws, both CVSS 9.1, disclosed December 9 and affecting FortiOS, FortiWeb, FortiProxy and FortiSwitch Manager. Dark Reading reports CISA added one of them to KEV citing evidence of active exploitation; check each CVE’s status in the catalog yourself rather than assuming both.
  • CVE-2026-24858 — a FortiCloud SSO authentication bypass (CWE-288) that CISA says allows an actor with a FortiCloud account and a registered device to log in to devices registered to other users across FortiOS, FortiManager, FortiWeb, FortiProxy and FortiAnalyzer. CISA added it to KEV in January 2026.
  • CVE-2026-35616 — a flaw in FortiClient EMS, an endpoint management server rather than edge gear. The Hacker News reports CISA added it to KEV on April 6, 2026, with fixes required of federal agencies by April 9, 2026. A three-day turnaround, in practice, before BOD 26-04’s timelines were in force.

Fortinet is a palmiq partner, and none of this is an argument against the platform. Every major edge vendor has a KEV history. The pattern is that authentication bypass and information disclosure flaws in internet-facing gear get exploited fast, and the fix window keeps shrinking.

How fast do you have to patch a KEV-listed firewall vulnerability?

For federal agencies under BOD 26-04, a vulnerability that is publicly exposed, KEV-listed, automatable and grants total system control must be remediated within three calendar days. Cloud Security Alliance analysts characterize that as the most aggressive standing remediation timeline in federal cybersecurity directives; Qualys describes it as a 72-hour remediation SLA.

There’s a second obligation people tend to miss. A Forward Networks community analysis of the directive reads the highest-risk tier as also requiring forensic triage of the asset to determine whether it has already been compromised. That’s an informal read, so confirm it against CISA’s implementation guidance before you plan around it — but the underlying point holds regardless. Patching closes the door. Triage tells you whether someone already walked through it, and that requires log retention and detection coverage on the edge device itself, which most small businesses don’t have in place.

FedRAMP’s notice lays out the phasing: agency policies had to support ongoing vulnerability remediation by August 7, 2026, with agencies evaluating and remediating on BOD 26-04 timelines by December 7, 2026.

What should be on an edge-device inventory for a small business?

Seven fields per device. That’s it:

  1. Model
  2. Serial number
  3. Current firmware version
  4. Public IP or exposure status
  5. Management interface reachability (can it be reached from the internet?)
  6. Support contract expiry
  7. Vendor end-of-support date

Firewalls, VPN concentrators, remote-access gateways, wireless controllers, anything with a public listener. One spreadsheet is fine to start. What matters is that it’s complete and current, because the first BOD 26-04 criterion — public exposure — cannot be evaluated at all without it.

Building the list the first time is mostly legwork: walk the racks, reconcile against your support contracts, confirm firmware from the devices themselves rather than from documentation. Keeping it current on a set review schedule is the whole job.

How do you find out if a FortiGate is end of support?

Check Fortinet’s official product lifecycle and supported-versions pages for your specific model and FortiOS branch. Don’t rely on memory, a reseller quote from three years ago, or a third-party summary — lifecycle dates move, and this is the single most common place an inventory goes stale.

Record the date in the inventory. Then put every device approaching end of support onto a budget line, well before the date arrives.

What do you do when a KEV vulnerability hits an end-of-support device?

You have three options: replace it, segment it hard enough that compromise is contained, or disconnect it. There is no fourth option, because the vendor is not shipping a patch.

Only one of those is cheap, and only if you budgeted for it in advance. That’s why the inventory and the refresh roadmap are the same project. An organization that knows its end-of-support dates a year or more out treats firewall replacement as a planned expense. An organization that finds out during a KEV advisory treats it as an emergency, and emergencies price accordingly.

palmiq builds edge-device inventories and multi-year lifecycle roadmaps for SMBs, government contractors and K-12 districts, and our 24/7 SOC provides the detection and log coverage that makes “was this device already compromised?” an answerable question. We can’t promise a three-day fix on hardware nobody supports — nobody can. We can make sure you’re never surprised by which hardware that is.

Want to see what a planned refresh looks like? Join our FortiGate Firewall Modernization Webinar for Healthcare — the lifecycle and inventory approach applies well beyond healthcare.

Want this handled for you?

We run managed IT, security and backup for organizations that would rather not read another article about it.

Speak to an expert

or call 703-336-9700