U.S. cybersecurity officials are considering shortening the default remediation window for actively exploited vulnerabilities from two weeks to three days, citing concerns that advanced AI models can accelerate attackers’ ability to find and weaponize flaws. The proposal, under discussion at CISA and the White House cyber office, would affect the agency’s Known Exploited Vulnerabilities (KEV) catalogue. Experts warn the move could strain agencies and private organizations, since rapid patching often requires careful testing and adequate resources.
U.S. Weighs Cutting Patch Deadlines To Three Days As Advanced AI Speeds Up Hacking

U.S. cybersecurity officials are weighing a proposal to sharply shorten the time federal civilian agencies have to remediate critical, actively exploited software vulnerabilities — potentially cutting the standard two‑week window to just three days — after warnings that new artificial‑intelligence tools can accelerate attackers’ ability to find and weaponize flaws.
Why Officials Are Considering Faster Deadlines
Officials and security experts say advanced AI models, including Anthropic’s Mythos and a model identified as OpenAI’s GPT‑5.4‑Cyber, are increasingly able to discover previously unknown bugs or turn newly disclosed flaws into high‑impact exploits in hours rather than days or weeks. That compression of the attacker timeline has prompted senior leaders at the Cybersecurity and Infrastructure Security Agency (CISA) and the White House cyber office to consider more aggressive default deadlines for fixing vulnerabilities.
How The Proposal Would Work
CISA maintains a Known Exploited Vulnerabilities (KEV) catalogue that lists flaws actively abused by criminals or state actors. Civilian agencies are generally expected to patch KEVs within two weeks of listing; the option under discussion would make a three‑day remediation window the default for actively exploited vulnerabilities, with exceptions for particularly complex or disruptive cases, according to people familiar with the talks.
If you’re going to protect civil agencies, you’re going to have to move faster,
said Stephen Boyer, founder of cybersecurity firm Bitsight, which has worked with CISA on cataloguing vulnerabilities.
Who Is Involved
Sources said the change is being discussed by Nick Andersen, acting head of CISA, and Sean Cairncross, the U.S. national cyber director. Reuters reported the deliberations but could not confirm whether a final decision has been made. CISA and the Office of the National Cyber Director did not immediately comment.
Challenges And Concerns
Security practitioners caution that a three‑day deadline would be difficult for many environments. Patching often requires testing, compatibility checks and staged rollouts to avoid disrupting critical services. "Realistically, three days is simply impossible for some environments," said Kecia Hoyt, vice president at threat intelligence firm Flashpoint.
Former CISA deputy director Nitin Natarajan, now head of consultancy NN Global, said stricter timelines could encourage state, local and private organizations to move faster but warned that CISA itself has faced staffing and funding cuts and must have the capacity to manage tighter deadlines.
John Hammond, senior principal security researcher at Huntress, described a shift from two weeks to three days as "quite a change," and said the industry’s ability to adapt will be tested over time.
Broader Impact
The proposal is unfolding as regulators and companies — particularly in the financial sector — reassess risk amid the arrival of more capable AI tools. If adopted, CISA’s tightened deadlines could become a model for state and local governments and private organizations, raising the bar for vulnerability response nationwide.
Reporting: The discussion was reported by Reuters, based on people familiar with the matter. The story includes comments from cybersecurity experts and former officials who caution about operational and resourcing challenges.
Reporting by Raphael Satter; Editing by Chizu Nomiyama.
Help us improve.




























