Skip to content
CISA Discontinues Weekly Vulnerability Bulletin Amid Risk-Based Shift

CISA Discontinues Weekly Vulnerability Bulletin Amid Risk-Based Shift

First seen 18 Sep 2026, 18:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC
  • CISA is ending its weekly vulnerability bulletin effective September 28, 2026.
  • The shift to a risk-based approach prioritizes vulnerabilities based on real-world risk factors.
  • CISA encourages both federal and non-government organizations to adopt this new prioritization strategy.

The Cybersecurity and Infrastructure Security Agency (CISA) announced it will cease its weekly vulnerability bulletin at the end of September 2026. This decision is part of a broader transition from severity-based vulnerability management to a risk-based approach, as outlined in a June Binding Operational Directive. The bulletin, which has been in operation since early 2004, provided details on newly disclosed vulnerabilities, including CVEs and severity scores. CISA's new strategy emphasizes prioritizing vulnerabilities based on real-world risk factors, such as evidence of exploitation and exposure, rather than relying solely on Common Vulnerability Scoring System (CVSS) scores. The agency has encouraged federal agencies and non-government organizations to adopt this risk-based approach. CISA's shift is in response to the increasing number of vulnerabilities and the challenges posed by AI-assisted security research. Although the weekly bulletins will end, CISA will continue to provide guidance on vulnerability management and has introduced the Stakeholder-Specific Vulnerability Categorization (SSVC) system for more nuanced analysis.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
CISA issues Binding Operational Directive
CISA released a directive outlining a shift from severity-based to risk-based vulnerability management for federal agencies.
The Register
2026-09-16
CISA announces bulletin discontinuation
CISA revealed it will stop publishing weekly vulnerability roundups as part of its new risk-based approach.
The Register
2026-09-18
CISA details new vulnerability management strategy
CISA emphasized the need for a risk-based approach to vulnerability management, urging organizations to prioritize based on real-world risk.
Yahoo

More articles in this cluster (2)

Following this threat?

Track Conti in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed