www.darkreading.com 17 Sept 2026, 21:23 UTC

CISA Will End Weekly Vulnerability Bulletins in Risk-Based Shift

CISA Will End Weekly Vulnerability Bulletins in Risk-Based Shift
CyberSIXT Evidence Panel Source marked as original reporting

THE US Cybersecurity and Infrastructure Security Agency (CISA) will discontinue its weekly vulnerability bulletins from 28 September 2026. The agency said the change supports a broader shift away from prioritising vulnerabilities solely by severity and towards assessing real-world risk.

Newly recorded vulnerabilities will continue to be available through CVE.org, while CISA recommends its Known Exploited Vulnerability (KEV) Catalog, Cybersecurity Alerts and Advisories, and vendor security alerts for actionable updates.

The change comes as vulnerability disclosures increase, leaving organisations with growing remediation backlogs. CISA’s analysis of vulnerability data from 2024 and 2025 found that the number of vulnerabilities actually exploited by attackers grew only marginally despite the overall rise in vulnerabilities, suggesting that attackers focus on a relatively small subset.

CISA’s approach considers factors including automated exploitation, technical impact, asset exposure and KEV status, rather than relying only on CVSS scores.

Security experts quoted in the report welcomed the risk-based focus but warned that ending the weekly bulletin could make tracking emerging threats harder, particularly for smaller organisations. Kevin Surace of TokenCore said KEV remains essential but may not identify serious threats before exploitation has been confirmed. Defenders will therefore need to combine CISA’s KEV data and advisories with vendor alerts and knowledge of the systems they operate.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline