ANTERAS
Antelace
ANTERAS ASM adds vulnerability priority assessment based on CISA "BOD 26-04" to its portal.
ANTERAS ASM has added a feature that allows users to view assessment results based on "BOD 26-04," published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), on its portal.
Update details
In addition to the existing "ANTERAS Priority," the Vulnerability Alert details screen in the ANTERAS ASM portal will now display "CISA Priority (BOD 26-04)."
CISA Priority is calculated based on the latest CISA Vulnerability information, using the following four indicators to determine the estimated deadline for addressing the issue.
- Externally Exposed
- Listing status in CISA KEV (Listed in CISA KEV)
- Automatability of misuse
- Technical impact if misused.
ANTERAS ASM displays estimated deadlines for addressing issues based on BOD 26-04 standards, assuming that the target assets are publicly available on the internet.
Towards prioritizing vulnerability countermeasures in a way that better reflects reality.
BOD 26-04 is a directive issued by the U.S. CISA on June 10, 2026, for U.S. federal civilian administrative agencies. It revises the previous uniform application based on CVSS scores and sets deadlines for action based on risks such as the public disclosure status of assets and a history of misuse.
Please use CISA Priority as reference information to confirm the positioning of vulnerabilities within the common CISA standards.
Regarding the actual order of response, we recommend prioritizing the "ANTERAS Priority," which reflects the insights of our researchers regarding threat trends and scope of impact.
For more details on BOD 26-04, please see below.
Inquiry/Document request
Macnica ANTERAS Department
- TEL:045-476-2010
- E-mail:sec-service@macnica.co.jp
Weekdays: 9:00-17:00