CISA's Binding Operational Directive 26-04 moves federal agencies away from CVSS severity scores toward a risk-based patching model. The framework evaluates four factors: internet exposure, presence in the Known Exploited Vulnerabilities catalog, exploit automation potential, and post-exploitation impact. Vulnerabilities meeting three or more criteria must be patched within three days; lower-risk ones can be deferred. Analysis of one federal agency found only ~1% of vulnerabilities required the three-day response, while 60%+ could wait for regular update cycles. Security experts broadly endorse the direction but flag limitations: KEV is retroactive and binary, covers only ~8% of observed exploitation, and the CVE assignment pipeline may be too slow as AI accelerates vulnerability discovery. Predictive tools like EPSS are recommended as better forward-looking signals. The directive is seen as a model likely to influence private-sector vulnerability management practices.