www.securityweek.com 17 Sept 2026, 14:28 UTC

CISA Ends Weekly Vulnerability Bulletin in Risk-Based Shift

CISA Ends Weekly Vulnerability Bulletin in Risk-Based Shift
CyberSIXT Evidence Panel Source marked as original reporting

THE US Cybersecurity and Infrastructure Security Agency (CISA) will discontinue its weekly vulnerability bulletin on 28 September, shifting towards risk-based vulnerability management. The bulletin summarised newly recorded vulnerabilities, including affected products, descriptions, publication dates, severity ratings, CVSS scores, CVE identifiers and available patch information. However, its entries covered thousands of flaws and did not explain which required urgent action, potentially contributing to alert fatigue.

CISA said the change aligns with Binding Operational Directive (BOD) 26-04, which requires US federal agencies to prioritise vulnerabilities using real-world risk factors, including evidence of exploitation and exposure, rather than severity scores alone. Published in June, the directive also requires agencies to review their vulnerability-management policies and prioritise vulnerabilities listed in CISA’s Known Exploited Vulnerabilities (KEV) catalogue.

CISA will continue publishing risk-focused information through the KEV catalogue, alerts and advisories. Security operations centres that used the weekly bulletin to track new vulnerabilities may therefore need to adjust their processes. The article presents the move as part of a wider shift away from relying solely on CVSS ratings, which measure theoretical technical severity, towards considering active exploitation, threat-actor interest and exposure.

View full article

Article by CyberSIXT