CISA Discontinues Weekly Vulnerability Bulletin Amid Risk-Based Shift
Article Content
- •CISA is ending its weekly vulnerability bulletin effective September 28, 2026.
- •The shift to a risk-based approach prioritizes vulnerabilities based on real-world risk factors.
- •CISA encourages both federal and non-government organizations to adopt this new prioritization strategy.
The Cybersecurity and Infrastructure Security Agency (CISA) announced it will cease its weekly vulnerability bulletin at the end of September 2026. This decision is part of a broader transition from severity-based vulnerability management to a risk-based approach, as outlined in a June Binding Operational Directive. The bulletin, which has been in operation since early 2004, provided details on newly disclosed vulnerabilities, including CVEs and severity scores. CISA's new strategy emphasizes prioritizing vulnerabilities based on real-world risk factors, such as evidence of exploitation and exposure, rather than relying solely on Common Vulnerability Scoring System (CVSS) scores. The agency has encouraged federal agencies and non-government organizations to adopt this risk-based approach. CISA's shift is in response to the increasing number of vulnerabilities and the challenges posed by AI-assisted security research. Although the weekly bulletins will end, CISA will continue to provide guidance on vulnerability management and has introduced the Stakeholder-Specific Vulnerability Categorization (SSVC) system for more nuanced analysis.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Conti in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…