VYPR
advisoryPublished Sep 16, 2026· 1 source

CISA Discontinues Weekly Vulnerability Bulletin, Shifts to Risk-Based Approach

CISA is phasing out its weekly vulnerability bulletin at the end of September, moving towards a risk-based approach prioritizing exploitation potential over severity scores.

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the discontinuation of its weekly vulnerability bulletin, with the final issue slated for release on September 28, 2026. This move signifies a strategic shift by the agency away from managing vulnerabilities based solely on severity scores towards a more dynamic, risk-based approach.

This new methodology is detailed in a Binding Operational Directive (BOD) issued in June. The BOD mandates that federal civilian agencies prioritize security updates based on the real-world risk of exploitation. This means that vulnerabilities will be assessed not just by their potential impact if exploited, but also by the likelihood of such exploitation occurring. Factors such as evidence of exposure, the degree of control granted by exploitation, and the potential for automated exploitation are now central to this prioritization.

The agency explained in its June announcement that this evolution of CISA's Known Exploited Vulnerabilities (KEV) catalog aims to increase mission readiness across the federal government. By efficiently prioritizing high-risk vulnerabilities, agencies can take timely action, while deferring efforts on those deemed lower risk. This approach moves covered federal civilian agencies away from an over-reliance on static CVSS scores alone when determining remediation priorities.

While CISA has outlined the new risk-based strategy, it has not provided a specific reason for discontinuing the weekly bulletin rather than adapting it to align with the new BOD standards. One potential factor could be the sheer volume of newly disclosed vulnerabilities. Advances in AI-assisted security research are rapidly increasing the number of patches released, and the broader CVE ecosystem, including the National Vulnerability Database, faces significant backlogs and challenges in filtering out potentially bogus AI-generated reports.

CISA emphasizes that this change does not mean organizations should abandon CVEs altogether. Instead, it directs those seeking to stay informed about vulnerability information to rely on CISA's KEV catalog, its cybersecurity alerts and advisories, and the CVE catalog itself. This requires users who previously subscribed to the weekly bulletin to actively update their subscriptions via their GovDelivery or Granicus accounts to ensure they receive notifications for the KEV Catalog and Cybersecurity Advisories.

Organizations that have relied on the weekly bulletin for a consolidated view of emerging threats will need to adjust their threat intelligence gathering processes. The agency's commitment to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk remains, but the method of communication for certain types of critical vulnerability information has changed. This transition underscores a broader industry trend towards more sophisticated, risk-aware vulnerability management strategies in the face of an increasingly complex threat landscape.

The discontinuation of the weekly bulletin highlights the evolving nature of cybersecurity information dissemination. As the volume of disclosed vulnerabilities continues to grow, driven in part by advanced research techniques, agencies like CISA are compelled to refine their methods for delivering actionable intelligence. The focus is shifting from a broad, periodic overview to more targeted, risk-informed alerts and curated catalogs of actively exploited threats.

Synthesized by Vypr AI