Trending: On-device modelsSearch
iHeartGeek
iTECH

CISA retires the weekly vulnerability bulletin

CISA will stop emailing its weekly round-up of new vulnerabilities on 28 September, folding the job into a risk-based model built around the Known Exploited Vulnerabilities catalogue.

A dark still life of neatly stacked blank paper bulletins lit in teal and amber, with a small cluster of glowing digital blocks floating above the pile.

What is CISA changing?

CISA is retiring its weekly Vulnerability Bulletin. A short notice at the top of the agency's bulletins page confirms that the digest, which has summarised newly recorded CVEs for years, will not continue past the end of the current US financial year. There was no press release and no announcement event. The bulletin simply acquired an expiry date.

The wording is worth quoting in full, because it explains the reasoning better than any summary: “CISA will discontinue the weekly Vulnerability Bulletin at the end of FY26 (September 28, 2026) as part of a broader shift from severity-based vulnerability management to risk-based vulnerability prioritization.”

When does the weekly bulletin stop?

28 September 2026 is the last issue. After that, newly recorded vulnerabilities remain available on CVE.org, the shared registry of published CVEs that CISA's bulletin was itself built from.

Why is CISA dropping it?

The change follows Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk, published on 10 June 2026. The directive supersedes and revokes two older rules, BOD 19-02 and BOD 22-01, and consolidates them into a single risk-based model.

Its central argument is that treating every vulnerability the same is a losing game. CISA's directive says the approach “focuses patching efforts on the areas of highest risk rather than treating all vulnerabilities and systems equally”, and it sets the urgency of remediation from four variables: whether the vulnerable asset is publicly exposed, whether the vulnerability sits on the Known Exploited Vulnerabilities catalog, whether an attacker can automate the whole exploitation chain, and how much control they gain if they succeed.

CISA publishes answers to three of those four for every CVE ID through its Vulnrichment Program, which is the practical plumbing that makes a risk-based queue possible at all. The directive also makes an argument that will sound familiar to anyone watching supply chains this year: attackers are exploiting unpatched flaws, and their use of AI “may further narrow the time defenders have to react between patch release and possible exploitation”.

What replaces the weekly bulletin?

Three things, in CISA's own ordering. First, the Known Exploited Vulnerabilities catalog, which the agency describes as its authoritative source of vulnerabilities exploited in the wild and says should be used as an input to a prioritisation framework. Second, CISA's Cybersecurity Alerts and Advisories. Third, vendor security alerts, which for most teams are the fastest route to a specific fix.

Readers who want to keep receiving automated updates can use CISA's Subscribe to Updates page. The difference is that nothing now arrives as a single curated weekly bundle.

What this means if you relied on the bulletin

The weekly digest was never the most sophisticated tool in a security team's kit, but it was dependable. It arrived on a schedule, it covered everything newly recorded, and it required no configuration. What replaces it is more accurate and less convenient: an exploited-in-the-wild list that is deliberately incomplete about severity, plus alert feeds you have to wire into your own processes.

Practically, that means three jobs move in-house. Someone has to watch the KEV catalogue rather than wait for it in an inbox. Someone has to decide which of your systems are publicly exposed, because exposure is now the first variable in CISA's own urgency calculation. And someone has to accept that a vulnerability with a low severity score and a working exploit automation path outranks a high-scoring bug with neither, which is the whole point of the new model.

Our opinion

Risk-based patching is the right idea and CISA is right that severity scores alone have been quietly misleading for years. A 9.8 that nobody has ever exploited and a 7.2 that is already being used in the wild are not the same problem, and the second one keeps getting buried under the first. The KEV catalogue is genuinely one of the most useful things a government has built for defenders.

The trouble is who absorbs the work. A weekly bulletin was crude, unranked and often ignored, but it was a floor that every team stood on, including the two-person IT department that has no vulnerability management platform and no one whose job title contains the word exposure. Replacing a universal list with a prioritisation framework moves the judgement call onto the defender, and judgement calls need context most small teams do not have. CISA is not wrong to stop mailing out raw material. It is asking a lot to assume everyone can now do the analysis themselves.

There is also a neat contradiction in the timing. The same directive that retires the weekly digest warns that AI is compressing the gap between a patch landing and an exploit appearing. Speeding up the threat while slowing down the delivery of information is a trade that only works if teams wire the feeds in properly. So do that: subscribe to the KEV updates, forward vendor alerts into the same channel your on-call rota reads, and write down which of your systems face the internet. Do not read the end of the bulletin as a smaller problem. It is the same problem with the training wheels taken off.

What we know
  • CISA will discontinue the weekly Vulnerability Bulletin at the end of FY26, with 28 September 2026 the final issue
  • Newly recorded vulnerabilities stay on CVE.org
  • The agency points readers to the Known Exploited Vulnerabilities catalog, its Cybersecurity Alerts and Advisories, and vendor security alerts
  • CISA says the change is part of a shift from severity-based to risk-based vulnerability prioritisation
  • Binding Operational Directive 26-04, dated 10 June 2026, supersedes and revokes BOD 19-02 and BOD 22-01
  • Under BOD 26-04 the urgency of remediation turns on asset exposure, KEV status, exploit automation and technical impact
  • CISA's directive notes that attackers' use of AI may narrow the time between a patch release and exploitation