The Cybersecurity Infrastructure and Security Agency this week released a binding operational directive this week requiring federal agencies to patch known exploited vulnerabilities carrying "significant risk" to the federal enterprise. The directive also established a catalog of nearly 300 vulnerabilities, each with an accompanying due date for taking action. Roughly a third