> ## Content Index
> Fetch the complete content index at: https://blog.disclose.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# Policy Pulse - Issue #31 | Week of August 30, 2026
- URL: https://blog.disclose.io/policy-pulse-issue-31-week-of-august-30-2026/
- Published: 2026-08-30T22:04:42.000Z
- Updated: 2026-08-30T22:04:42.000Z
- Description: CISA puts it in a directive: the CVE program is not a comprehensive list of vulnerabilities, and agencies should remediate the gaps anyway. Plus 43 Section 1201 renewal petitions land, and one frontier lab stays silent 11 weeks.
- Author: Disclose.io
- Tags: Policy Pulse, policy

# Policy Pulse - Issue #31 | Week of August 30, 2026

*Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.*

---

### Top Story

**CISA puts it in writing: the CVE program is not the whole map**

On August 25, CISA refreshed the implementation guidance for [Binding Operational Directive 26-04](https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk?ref=blog.disclose.io), adding forensic triage steps and an extensive FAQ. Buried in that FAQ is the most useful sentence a federal agency has written about vulnerability management this year. Asked whether the CVE database or the Vulnrichment program is the full list of vulnerabilities an agency needs to worry about, CISA answers: "No. The CVE program is not a comprehensive list of cybersecurity vulnerabilities. Some cybersecurity vulnerabilities are excluded from receiving CVE IDs. This decision is an important feature of the numbering rules that help keep the CVE system usable."

It then names the two classes that fall through. Web application vulnerabilities are "often unique configurations of a web service that would not qualify for a CVE ID, agencies should still remediate." The second is "exploitable configurations of authentication and identity management systems." Anyone who has run a bug bounty or VDP intake queue recognises both immediately. They are the daily bread of real-world disclosure and they are structurally invisible to CVE-denominated metrics.

The same guidance made this week's KEV additions legible in a way earlier batches were not. Pulling CISA's [Known Exploited Vulnerabilities feed](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?ref=blog.disclose.io) directly (catalog version 2026.08.27, 1,685 entries), eleven CVEs were added across August 24 to 27, and the remediation windows split cleanly in two rather than landing on a single uniform deadline. Six carry a three-day due date: CVE-2026-21962 (Oracle HTTP Server and WebLogic Proxy Plug-in), CVE-2026-60004 (Gitea), CVE-2019-1068 (Microsoft SQL Server), CVE-2026-8452 (Citrix NetScaler ADC and Gateway), CVE-2023-49105 (ownCloud), and CVE-2026-53362 (Linux kernel). Five carry fourteen days: CVE-2015-3246 (Red Hat Libuser), CVE-2015-5287 (Red Hat ABRT), CVE-2021-23758 (Ajax.NET Professional), CVE-2022-0995 (Linux kernel), and CVE-2026-66384 (JFrog Artifactory). That is BOD 26-04's risk matrix, which replaced flat CVSS-based deadlines, showing up as observable data for the first time. (Tier assignment is our own computation from the published feed dates, not a CISA statement.)

**Why it matters for VDP:** Two things break at once. Any program document, SLA, or advisory template that says "CISA requires remediation within three weeks" is now simply wrong, because the federal clock is per-CVE and derived from automatability and technical impact. And the CVE-scope concession is the first federal directive text we have seen that can be cited directly when a program owner argues a finding "does not count" because it never got an identifier. It counts. CISA says so, in an operational directive, in writing.

*📎 Throwback: In [Issue #30](https://blog.disclose.io/policy-pulse-issue-30-week-of-august-23-2026/) we tracked the nine KEV additions of August 17 to 21\. This week's eleven are a separate batch, and note the deliberate backfill of decade-old CVEs from 2015 alongside fresh ones.*

---

### Upcoming Deadlines & Events

| Date             | Agency              | Event/Deadline                                                                                         | Action Required                                                      | Link                                                                                                                                                                                                  |
| ---------------- | ------------------- | ------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Sep 7, 2026**  | NIST                | Comments close on CSWP 36F, Initial NAS Message Security (5G)                                          | Submit comments                                                      | [NIST CSRC](https://csrc.nist.gov/News/2026/comment-on-nccoe-initial-public-draft-cswp-36f?ref=blog.disclose.io)                                                                                      |
| **Sep 8, 2026**  | NIST                | Comments close on SP 800-209 Rev. 1, storage infrastructure security                                   | Submit comments                                                      | [NIST CSRC](https://csrc.nist.gov/pubs/sp/800/209/r1/ipd?ref=blog.disclose.io)                                                                                                                        |
| **Sep 11, 2026** | EU / ENISA          | CRA Article 14 reporting obligations begin                                                             | Stand up 24h/72h/14-day reporting; identify your coordinating CSIRT  | [CRA readiness](https://www.cyberresilienceact.eu/news/cra-reporting-readiness-what-to-prepare-before-11-september-2026.html?ref=blog.disclose.io)                                                    |
| **Sep 25, 2026** | NIST                | Comments close on SP 800-239, AI data center security                                                  | Submit comments                                                      | [NIST CSRC](https://csrc.nist.gov/pubs/sp/800/239/ipd?ref=blog.disclose.io)                                                                                                                           |
| **Sep 28, 2026** | US Copyright Office | Comments due in response to §1201 renewal petitions                                                    | Support renewal of the security research exemption                   | [copyright.gov](https://www.copyright.gov/1201/2027/?ref=blog.disclose.io)                                                                                                                            |
| **Oct 1, 2026**  | Zero Day Initiative | Pwn2Own Ireland registration closes, 5:00 pm IST or at 80 complete registrations, whichever is earlier | Register via [pwn2own@trendmicro.com](mailto:pwn2own@trendmicro.com) | [ZDI rules](https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html?ref=blog.disclose.io)                                                                                                      |
| **Oct 5, 2026**  | NIST                | Comments close on IR 8613, multi-cloud architecture                                                    | Submit operational evidence                                          | [NIST CSRC](https://csrc.nist.gov/pubs/ir/8613/ipd?ref=blog.disclose.io)                                                                                                                              |
| **Oct 13, 2026** | NIST                | Comments close on NVD modernization RFI (docket NIST-2026-0100)                                        | Tell NIST what disclosure infrastructure needs                       | [Federal Register](https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of?ref=blog.disclose.io) |
| **Oct 15, 2026** | NIST                | Comments close on SP 1353, AI for CSF 2.0                                                              | Review prompts and submit comments                                   | [NIST CSRC](https://csrc.nist.gov/pubs/sp/1353/ipd?ref=blog.disclose.io)                                                                                                                              |

---

### This Week in Policy

#### AI & Emerging Tech Security

- **A frontier lab went dark on a zero-click data-theft report for eleven weeks.** Adversa AI published "Cryptographic Context Injection" on August 20, hiding attacker instructions inside AES-256-GCM ciphertext so input filters never parse them, then inducing the agent to decrypt and trust its own output. The chain leaks the user's name, coarse location, subscription tier, and the full set of prompts in the conversation to an attacker-controlled endpoint. Adversa reported it to xAI on June 3, got an acknowledgement with "no specifics and no mitigation timeline," followed up on August 4 and August 10, and wrote: "As of the date of writing, we have received no response." The same technique worked against Google Gemini's Deep Thinking mode, where success rates "had dropped significantly by August." ([Adversa AI](https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/?ref=blog.disclose.io), [The Hacker News](https://thehackernews.com/2026/08/new-cryptographic-context-injection.html?ref=blog.disclose.io)) **Why it matters for VDP:** the researchers are explicit that this is not a model bug. "You do not need to fix this at the model layer. Every control that bounds this attack sits in the harness around the agent." Intake triage that routes anything labelled "AI vulnerability" into a model-safety queue will misfile this entire class. Agentic frameworks, tool-invocation layers, and session-context resolution need their own path.
- **Over a hundred companies called for a defensive surge, and said nothing about disclosure.** On August 27, OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet, and more than a hundred other signatories published an open letter warning that "in the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." The asks are adoption of new cyber defense forms, collaboration across local, national, and international levels, and new partnerships to raise security standards. ([TechCrunch](https://techcrunch.com/2026/08/27/openai-anthropic-google-and-100-other-companies-call-for-action-to-defend-against-rogue-ai/?ref=blog.disclose.io)) **Why it matters for VDP:** we went looking for vulnerability disclosure, bug bounties, red teaming, or security researchers in the coverage and found none of them. A hundred-company call for a defensive surge that never mentions the coordinated disclosure ecosystem is a gap worth naming out loud, particularly in a week when a live agentic-framework report sat unanswered for eleven weeks.

#### Federal Strategy & Regulation

- **Executive Order 14420 declares a national emergency over bulk-power equipment.** Signed August 26 under IEEPA, it prohibits covered transactions in foreign-supplied bulk-power system electric equipment and gives the Secretary of Energy 120 days to issue implementing regulations. ([White House](https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/?ref=blog.disclose.io)) **Why it matters for VDP:** the order's scope explicitly reaches "associated software and firmware, remote access capabilities, lifecycle maintenance and update mechanisms, and other supply chain dependencies." Researchers reporting flaws in covered grid equipment now face a supply-chain provenance question stacked on top of the ordinary disclosure one.
- **CISA red-teamed two critical infrastructure organizations and published the comparison.** Advisory [AA26-237A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a?ref=blog.disclose.io), released August 25, reports that "in both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team" to change approach. **Why it matters for VDP:** compromise was universal, response was not. That is the same thesis underneath disclosure program maturity scoring: the differentiator is never whether findings exist, it is whether the receiving organization can act on them.

#### CVE & Vulnerability Programs

- **Citrix called it a denial of service. It was unauthenticated RCE.** CVE-2026-8452 was disclosed June 30 as a "memory overflow vulnerability leading to unpredictable or erroneous behavior and denial of service." watchTowr Labs published analysis and a working proof of concept on August 14 demonstrating full unauthenticated remote code execution, with attackers dropping web shells on compromised systems. CISA added it to KEV on August 26 with a three-day federal deadline. ([Help Net Security](https://www.helpnetsecurity.com/2026/08/27/netscaler-adc-gateway-cve-2026-8452/?ref=blog.disclose.io)) **Why it matters for VDP:** defenders who triaged off the vendor's own severity characterisation deprioritised an internet-facing RCE for roughly eight weeks. Vendor-assigned severity is an input to triage, not a substitute for it.

#### Legal & Researcher Protections

- **UK peers move to force a Computer Misuse Act review.** An amendment to the Cyber Security and Resilience Bill, backed by Tim Clement-Jones and introduced the week of August 24, would give the government twelve months from the bill's passage to report to Parliament. His explanatory statement: "This new clause seeks to place a statutory duty on the secretary of state to review, within 12 months, whether a statutory defence under section one of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK's cyber resilience, and to report to Parliament." The CyberUp campaign responded that "providing legal certainty for legitimate cyber security activity is essential to strengthening the UK's cyber resilience." Campaigners put the economic upside of a statutory defence at up to £2.4bn per year. ([Computer Weekly, Aug 27](https://www.computerweekly.com/news/366649543/Peers-propose-report-into-Computer-Misuse-Act-reform?ref=blog.disclose.io)) **Why it matters for VDP:** a duty to review is not a statutory defence, and two previous attempts died in 2024 and 2025\. But it keeps the only Five Eyes reform vehicle with real parliamentary momentum alive.
- **Section 1201 renewal petitions are in: 43 filed, four for security research.** The August 24 deadline passed and the Copyright Office has now posted the renewal petitions for the tenth triennial proceeding. Four seek renewal of the security research exemption, filed by Blaze and Bellovin, Michael A. Specter, the Software Freedom Conservancy, and MEMA. A separate petition from the Coalition of Medical Device Patients and Researchers covers medical device data. Petitions for newly proposed exemptions are not yet published. ([copyright.gov](https://www.copyright.gov/1201/2027/petitions/renewal/?ref=blog.disclose.io)) **Why it matters for VDP:** written comments in response to renewal petitions are due September 28, 2026, and renewed exemptions run October 2027 to October 2030\. This is the cheapest, highest-leverage filing window in the whole proceeding, and supporting comments genuinely matter to the Register's recommendation.

*📎 Throwback: [Issue #30](https://blog.disclose.io/policy-pulse-issue-30-week-of-august-23-2026/) flagged the August 24 petition deadline. Now we know who showed up.*

#### International Developments

- **German computer scientists want the "hacker paragraphs" rewritten.** On August 25 the Gesellschaft für Informatik, working with industry, cybersecurity research, and digital policy partners, published a white paper calling for reform of sections 202a to 202c of the German Criminal Code, singling out §202c which "already criminalizes the provision and use of tools necessary for sound security analysis." The demands: make specific intent to cause harm an element of the offence, protect those who properly report a vulnerability to the manufacturer or responsible bodies, and adapt copyright, trade secrets, and data protection law to match. It cites Poland, Belgium, and Portugal as jurisdictions that have already built a legally secure framework for ethical hacking. ([GI](https://gi.de/meldung/zeit-zu-handeln-gi-legt-whitepaper-zur-reform-des-computerstrafrechts-vor?ref=blog.disclose.io), [heise](https://www.heise.de/en/news/Computer-scientists-demand-legal-protection-for-security-researchers-11424330.html?ref=blog.disclose.io)) **Why it matters for VDP:** §202c is the reason a great deal of European security tooling work happens quietly. Reform there would change the operating conditions for a large research community, and the Poland/Belgium/Portugal comparison is a useful precedent set for anyone arguing the same case elsewhere.
- **The EU CRA reporting clock starts in under two weeks.** Article 14 of the Cyber Resilience Act applies from September 11, 2026, imposing a 24-hour early warning, a 72-hour notification where "the substance becomes mandatory," and a final report no later than 14 days after a corrective measure is available for a vulnerability, or within one month of the 72-hour notification for a severe incident. Reports route to "the CSIRT designated as coordinator in the Member State of your main establishment." As of the August 24 readiness analysis the ENISA Single Reporting Platform is "not yet live," though ENISA has scheduled it to be operational by September 11, and "no reporting API is offered at this stage." ([cyberresilienceact.eu](https://www.cyberresilienceact.eu/news/cra-reporting-readiness-what-to-prepare-before-11-september-2026.html?ref=blog.disclose.io)) **Why it matters for VDP:** every manufacturer selling into the EU acquires a legally binding 24-hour clock for actively exploited vulnerabilities, against a portal nobody has been able to rehearse on and with no automation path. Prepare the three-stage notification language now, because you will be drafting it under a one-day deadline otherwise.

---

### Friends of disclose.io

**W3C Security Interest Group: a disclosure process for standards, not software**

On August 24 the W3C Security Interest Group published the first Group Note Draft of [Standards Vulnerability Disclosure & Handling Process and Policy](https://www.w3.org/TR/2026/DNOTE-security-disclosure-20260824/?ref=blog.disclose.io). It is a small document with an unusually interesting premise: a coordinated disclosure process aimed at design flaws in specifications themselves, rather than at the code that implements them.

From the abstract: the document "defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes. It is not for reporting vulnerabilities in software implementations or W3C operational infrastructure."

That boundary is the whole point, and it exposes a real gap. Existing CVD frameworks assume a vendor, a patch, and a version. A specification has none of those. It has maturity levels, and a flaw in a Recommendation is a fundamentally different problem from the same flaw in an Editor's Draft, because one of them is already implemented in every browser on earth.

**Key points:**

- In scope: design vulnerabilities and security issues described in W3C specifications
- Out of scope: implementation and configuration vulnerabilities in products, plus W3C's own infrastructure
- Routing differs by document maturity, which is the structurally novel part
- Status is Group Note Draft on the Note track, so it is genuinely open to influence right now
- Feedback goes through GitHub at [w3c/security-disclosure](https://github.com/w3c/security-disclosure?ref=blog.disclose.io), with no stated deadline

📄 [Read the draft](https://www.w3.org/TR/security-disclosure/?ref=blog.disclose.io)

*This is exactly the constituency disclose.io exists to serve, and a draft with no comment deadline and an open GitHub repository is about as low-friction as policy participation gets. If you have ever filed a report that died because nobody could work out who owned the flaw, this is the document to read.*

---

### Worth Reading

- **[CISA BOD 26-04 implementation guidance FAQ](https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk?ref=blog.disclose.io)**: skip to the Vulnrichment and CVE Database section. It is the clearest official statement of what CVE identifiers do and do not cover.
- **[NIST IR 8611, m-NGAC](https://csrc.nist.gov/pubs/ir/8611/final?ref=blog.disclose.io)**: finalised in August, embeds NGAC access control inside the database so enforcement holds at column level "regardless of the querying tool, including SQL editors." A direct answer to the perennial finding where application-layer authorization is bypassed by direct database access.
- **[Adversa AI on cryptographic context injection](https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/?ref=blog.disclose.io)**: read it for the harness-versus-model argument even if you never touch an agentic system. It is the clearest articulation yet of where AI security bugs actually live.
- **[NIST NVD modernization RFI](https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of?ref=blog.disclose.io)**: comments close October 13\. If AI-scale discovery is going to break the disclosure pipeline, this is where you say so on the record.

---

*Policy Pulse is a weekly bulletin from [disclose.io](https://disclose.io/?ref=blog.disclose.io). Keeping the security research community informed on policy that affects our work.*

*Have a tip or want to contribute? Reply to this email, reach out on [Twitter/X](https://twitter.com/disclose%5Fio?ref=blog.disclose.io), or drop a comment here!*