CISA issued Emergency Directive 26-02 requiring all federal agencies to patch a critical VPN appliance vulnerability within 72 hours.

The agency confirmed active exploitation by nation-state actors targeting sensitive government networks.