The federal government gave its own agencies a patch deadline today. Three bugs in widely used Cisco, Chrome, and Arista products were added to a public list of vulnerabilities that attackers are already exploiting in the wild, and every federal agency had to push fixes by 2026-06-23 or pull the affected systems off the network. The deadline is a federal mandate, not a small-business rule. But the same software, the same browsers, and in many cases the same network gear sit inside the small offices an outsourced IT team supports every day. When the federal clock starts, the practical question for a small-business owner is whether the office should be running on the same schedule or weeks behind it.

What Is The CISA Known Exploited Vulnerabilities List?

The Cybersecurity and Infrastructure Security Agency publishes a public catalog called the Known Exploited Vulnerabilities list. The list is exactly what the name says. It only contains bugs that the agency has confirmed are being used in real attacks against real organizations, with sourced evidence behind each entry. Theoretical flaws that researchers found in a lab do not make it onto the catalog. A bug shows up when somebody has already been hit by it.

Each entry carries a vendor name, a product family, the vulnerability identifier, a short plain-English description, and a fixed deadline by which federal agencies are required to patch or stop using the product. The catalog has grown past 1,200 entries since the agency launched it in late 2021, and roughly two hundred items get added every year as new attacker techniques surface. The full list is free to read on the agency website and is searchable by vendor, product, or date added.

The list is technically a federal-civilian compliance mechanism. It exists because the executive branch needed a single source of truth for which patches federal IT teams have to prioritize before the next quarterly review. The agency is not telling private businesses what to do. It does not have that authority. What it does provide, though, is a free public scoreboard of the bugs that attackers are actually using this month, ranked by how fast the federal government decided they had to be fixed.

That second use is what makes the catalog interesting for a small business. The list is a free, vendor-neutral, evidence-backed reading of which patches matter most right now. A small-business owner who has never logged into the agency website can still benefit from the catalog because the managed IT provider supporting the office is supposed to be tracking it on the business’s behalf.

Which Three Bugs Triggered Today’s Federal Deadline?

The three vulnerabilities added on June 9 with a June 23 deadline cover products that show up in small-business networks far more often than the federal-agency framing suggests. One is a flaw in Cisco Catalyst SD-WAN Manager, the management plane that ties together branch-office routers in many distributed-business networks. One is in Arista network operating systems, a less-common but still widely deployed enterprise switching platform. And one is in Google Chrome, the browser that is sitting on virtually every workstation in every small office in the country.

The Chrome entry is the one most small-business owners should pay attention to first. A browser bug that is being actively exploited is a different kind of risk than a server bug, because the attack does not require somebody to break into the office network. It only requires an employee to load a web page. The fix is straightforward (close the browser, let it update, reopen it) but the rollout across a thirty-person office can stall for a week if nobody is watching whether the updates actually applied. A patched browser that still has the old version running in a forgotten background tab is not a patched browser.

The Cisco SD-WAN management bug is narrower in scope but more dangerous when it hits. SD-WAN Manager is a centralized administration platform, so a successful exploit against it gives the attacker the ability to push configuration changes to every router under its control. Small businesses with distributed offices, retail locations, or remote-worker concentrators frequently sit on this platform without realizing the management appliance itself is the high-value target. The way a single Microsoft zero-day can hit every workstation at once is the closest analogy on the workstation side. On the network side, an SD-WAN Manager compromise is the same shape: one bug, every endpoint that platform manages.

The Arista bug is the least likely to be present in a small office because Arista gear concentrates in larger campuses and data centers. But the principle still applies. If a network device the business owns is on the federal list, it has been confirmed compromised somewhere already, and the patch is not optional. Whether a particular small office has Arista equipment in its closet is a fifteen-second check for any competent IT provider.

Why Should Small Businesses Match The Federal Patch Clock?

The argument for matching the federal deadline is not about regulation. Small businesses are not subject to the federal directive that produced today’s clock. The argument is about attacker behavior. Attackers do not check whether a target is federal before they exploit a public catalog entry. They scan the public internet for any system running the vulnerable version, and the small businesses on that list get hit with the same automated tooling as everybody else. In many cases the small businesses get hit first because their patch cycles are slower and the return on a successful exploit is the same.

The federal deadline is two weeks from the day the bug was added. That window is a deliberate compromise between operational reality (federal agencies cannot patch every system in 24 hours) and threat reality (attackers are already using the bug). For a small business, two weeks is a reasonable floor. Faster is better. Patching the same week the bug is added is the gold standard. Slower than two weeks is where the risk curve starts bending sharply upward, because by then the exploit code is mature, the automated tools have absorbed it, and the attack surface has stopped narrowing.

The other reason to match the cadence is operational rather than security-driven. A small business that runs a written emergency patch plan that ranks systems by exposure spends less total time on patching than a business that waits for breach pressure to force ad hoc work. The federal deadline gives the IT provider a forcing function. Without an external clock, patches slip behind feature requests and helpdesk tickets every month, and the technical debt compounds. With an external clock, the provider has a clean justification for clearing other work to do the patch.

The cost case is also more straightforward than most owners assume. The downtime cost of a missed patch that turns into a breach runs to several days of office disruption, customer-notification work, insurance claims, and recovery labor. The downtime math behind a managed network security program is the same shape every time. The patching itself, run on schedule, takes hours per month. The recovery work after a missed patch takes weeks per incident. The two numbers are not in the same range.

What Should A Small-Business Patch Cadence Actually Look Like?

A small-business patch cadence has three layers, and the layers run on three different clocks. The first layer is operating-system and browser updates. Those run continuously in the background on every workstation, with a managed agent confirming that the updates actually applied within twenty-four hours of release. The second layer is application updates for the third-party software that lives outside the operating-system update path. Those run on a weekly cycle, with a designated maintenance window when restarts can happen without disrupting work. The third layer is network and infrastructure updates, including the router firmware, the wireless controller, the firewall, the switch management plane, and the office NAS. Those run on a monthly cycle by default and accelerate to a same-week cycle when an item lands on the federal exploited-vulnerabilities catalog.

The cadence only works if somebody is verifying that the patches actually applied. A managed update agent that reports “pending” for three weeks is not a patched system. The verification layer is where most small-business patch programs break down, because the original install was successful but the reboot to finalize it never happened. A managed IT provider that is doing the job right will produce a monthly patch-status report that lists every device, the patch level it is currently running, and the date that level was confirmed. An owner who has never seen this report from the current provider should ask why.

When the patch itself is delayed for a legitimate operational reason (a key business application that breaks under the latest browser, a network device that requires after-hours maintenance), the right response is compensating controls rather than just hoping for the best. That means tighter stronger multi-factor authentication on the WAN-facing admin interfaces, increased logging on the affected system, and a defined date for when the underlying patch will be applied. The compensating controls are temporary scaffolding. They are not a permanent substitute for actually patching the bug.

The same cadence framework applies to security advisories that have not yet hit the federal catalog. The list is a lagging indicator. By the time a vulnerability is on it, attackers have been using it for weeks or months. A small business that only patches what the federal list flags is patching late. The list is a useful floor, not a useful ceiling. The actual patch cadence should be driven by vendor advisories the week they come out, with the federal list serving as the hard backstop for the highest-priority items.

How Should You Audit Your IT Provider This Week?

The single most useful question to ask a current IT provider this week is whether they track the federal exploited-vulnerabilities catalog as part of their managed-services contract. The answer should come back within a sentence or two. A provider who tracks the catalog will be able to name the three items that landed in early June, explain which ones touch the business’s environment, and describe what they did about each one. A provider who has never heard of the catalog or who needs a week to research the question is signaling that the patch program is reactive rather than proactive.

The second useful question is about verification. The owner should ask to see the most recent patch-status report covering every workstation, every server, every network device, and every cloud-connected appliance in the environment. The report should include the date each system was last confirmed patched, the patch level it is currently running, and any systems that are knowingly out of compliance. If the provider cannot produce this report on demand, the patch program is not actually being managed. It is being assumed.

The third useful question is about communication. When a new federal catalog entry lands on a Tuesday afternoon, the owner should expect to hear from the provider within one business day with a short note: what the bug is, whether the business is exposed, what the provider is doing about it, and when the work will be complete. That note is the single best indicator of whether the provider treats the office as a managed environment or as a collection of devices that someone gets paged about when something breaks.

Frequently Asked Questions About Federal Patch Deadlines

Does the CISA Known Exploited Vulnerabilities list legally apply to my small business?

No. The federal directive that produced the catalog only binds federal civilian agencies. Private businesses are not required to follow the deadlines. The list is still useful for small businesses because it tells you which bugs attackers are actively using, but using the list is a security best practice rather than a legal obligation. The exception is when a cyber-insurance policy, a customer contract, or an industry-specific regulation references the catalog as a benchmark, which is increasingly common in healthcare, finance, and government-adjacent contracts.

How often is the catalog updated?

The agency updates the catalog whenever new exploited vulnerabilities are confirmed, which usually means several updates per month and occasionally several updates per week during a busy threat period. A typical year adds roughly two hundred entries. The catalog is published as a web page, an RSS feed, and a downloadable JSON file, so a managed IT provider can wire the feed directly into a patch-management workflow that automatically prioritizes the affected systems.

What if I cannot patch a system within two weeks?

The right answer is rarely to skip the patch. It is to add temporary compensating controls and a written date by which the patch will be applied. Compensating controls include locking the affected system down to known-good IP addresses, adding stronger authentication on management interfaces, increasing logging and monitoring on the system, and limiting which user accounts can reach it. The controls are scaffolding that buys time. They are not a long-term substitute. The underlying patch still has to happen, and the longer it slips the higher the breach risk climbs.

Are Chrome updates really worth treating as a federal-deadline event?

Yes, when the federal list flags a Chrome bug specifically. Browser vulnerabilities that show up on the catalog are by definition being exploited through the browser, which means the attack path is “employee loads a web page” rather than “attacker breaks into the network first.” That is the most efficient delivery mechanism attackers have, which is why Chrome bugs that hit the catalog are usually patched by Google within hours of confirmation. The remaining work is making sure the patch actually rolled out and was applied across every workstation, which is the part that small offices miss most often.

How do I find out if my office has any of the affected products?

The managed IT provider should already have an inventory of every system, application, and network device the business owns, with the vendor, product, version, and patch level for each one. If the provider has that inventory, the answer to “are we exposed to today’s catalog additions?” is a five-minute lookup. If the provider does not have that inventory, building one should be the first project of the next month. A patch program without an asset inventory is patching in the dark, and the federal catalog is the most useful possible forcing function for finally getting the inventory built.

What is the difference between a CVE and a KEV entry?

A CVE is a Common Vulnerabilities and Exposures identifier, which is assigned to every documented software flaw regardless of whether the flaw is being exploited. The CVE database now contains more than two hundred thousand entries. The KEV catalog is the small subset of those CVEs that have been confirmed in active exploitation against real organizations. Every KEV entry has a corresponding CVE identifier, but only a small fraction of CVEs ever become KEVs. The two databases work together. The CVE database tells you what bugs exist. The KEV catalog tells you which ones attackers are actually using right now.

Should my employees check the catalog themselves?

No, except for the IT lead. The catalog is a technical document aimed at IT and security teams, and the entries assume the reader understands product names, version numbers, and patch processes. The right division of labor is for the IT provider or in-house IT lead to track the catalog and translate any business-relevant entries into a short owner-facing summary. Employees should follow the standard rule of installing every update prompt as soon as it appears and restarting devices when asked. That habit, applied consistently, covers most of the workstation-side exposure the catalog flags.

When Should You Bring In Professional Help?

If the current IT arrangement cannot answer “are we exposed to today’s federal patch additions, and what is being done about each one” within one business day, the patch program needs an upgrade. Treasure Coast small businesses that want a managed approach where the IT team tracks the federal catalog, runs the patch cadence, and produces the monthly verification report can talk to the O&O Systems team about what a proactive program looks like for a thirty-to-two-hundred-employee office.