Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
end-of-life-softwareperimeter-device-exposureactively-exploited-vulnerabilitycybersecurity-regulation

CISA Binding Operational Directive to Remove End-of-Life Edge Devices Amid Active Exploitation

Updated 3mo agoFirst seen Feb 5, 202610 sources

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD) ordering federal civilian agencies to identify and remove end-of-life/end-of-service (EOS), internet-facing edge devices—citing widespread active exploitation by sophisticated threat actors, including activity with ties to nation-states. CISA warned that unsupported devices remain in service long after vendors stop providing firmware and security updates, making them persistently vulnerable to exploitation and a recurring entry point for high-impact intrusions.

The directive requires agencies to inventory unsupported edge devices within three months, decommission/replace identified EOS devices on an accelerated timeline (reported as within one year for removal), and establish ongoing processes for continuous discovery/monitoring to prevent unsupported technologies from re-entering networks. Device categories called out include common perimeter and network infrastructure such as firewalls, routers, load balancers, switches, wireless access points, network security appliances, and IoT edge devices; CISA is also producing a government-wide list of EOS edge devices to guide compliance. Officials emphasized the action is not tied to a single incident, but reflects the sustained risk and observed exploitation of unsupported edge infrastructure across federal environments, while encouraging non-federal organizations to adopt similar practices.

Share:
CISA Binding Operational Directive to Remove End-of-Life Edge Devices Amid Active Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 5, 20265mo ago

CISA creates nonpublic EOS edge device list and begins compliance support

CISA created an end-of-support edge device list to help agencies identify affected products, versions and support dates, but said the list would not be published publicly. The agency said it developed the directive with OMB and would track agency compliance while providing implementation support such as guidance and reporting templates.

Directive sets inventory, replacement and lifecycle-management deadlines

The directive requires agencies to inventory end-of-support edge devices within three months, decommission or replace unsupported devices within one year, and establish an ongoing process within two years to identify devices approaching or reaching end of support. It also calls for immediate upgrades where hardware is still vendor-supported but running unsupported software, when operations will not be disrupted.

CISA issues BOD 26-02 on unsupported federal edge devices

On Feb. 5, CISA issued Binding Operational Directive 26-02 ordering U.S. federal civilian executive branch agencies to address end-of-support edge devices because of widespread exploitation risk. The agency said unsupported internet-facing devices such as firewalls, routers, load balancers and similar perimeter systems are being targeted by advanced and in some cases nation-state-linked actors.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Threat actors
2 linked
Organizations
8 linked
Security AffairsBarracuda NetworksXcape IncFortinetIvantiMicrosoft CorporationIntegrity Security ServicesPhosphorus Cybersecurity
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

CISA Binding Operational Directive to Remove End-of-Life Edge Devices Amid Active Exploitation | Mallory