[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5KGUa6e68slH7duTBcIQzvKhPdytQpuYRCFas4p1Aqc":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"3f115340-86e2-4bc5-a456-144b42db3ad3","CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot","cisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot-15484f","The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.","CISA is discontinuing its weekly vulnerability bulletin on September 28th, moving towards a risk-based vulnerability management strategy. This change aligns with Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize vulnerabilities based on real-world exploitation and exposure, rather than solely on severity scores. The agency will continue to provide risk-focused information through its Known Exploited Vulnerabilities (KEV) catalog, alerts, and advisories.","CISA retires its weekly vulnerability bulletin, shifting to a risk-based approach.","The US Cybersecurity and Infrastructure Security Agency (CISA) announced on Wednesday that it’s retiring its weekly vulnerability bulletin. The vulnerability bulletin will be discontinued on September 28 as part of a shift to a risk-based approach in vulnerability management. The bulletin provides a summary of new vulnerabilities recorded each week. It includes information such as product name, description of the flaw, the date of publication, severity, CVSS score, CVE identifier, and patch information (when available). Each bulletin contains entries for thousands of vulnerabilities, sorted alphabetically by affected product name and severity, but it does not provide guidance on prioritizing the security holes. Without threat intelligence or context on active exploitation, the sheer volume of flaws can lead to alert fatigue for defenders. CISA noted that the discontinuation of the bulletin “aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.” BOD 26‑04, published in June, required federal agencies to review and update their vulnerability management policies and prioritize the remediation of flaws included in the KEV catalog.Advertisement. Scroll to continue reading. In recent years there has been a broad industry transition away from relying solely on CVSS metrics. While CVSS measures theoretical technical severity, modern risk-based vulnerability management frameworks prioritize active exploits, threat actor interest, and exposure level. Since its introduction in 2021, CISA’s Known Exploited Vulnerabilities (KEV) catalog has largely eclipsed generic vulnerability summaries as the primary reference point for defenders. By focusing strictly on bugs with documented in-the-wild exploitation, the KEV list provides actionable prioritization that static weekly bulletins could not match. However, with the weekly bulletin gone, security operations centers (SOCs) that have relied on it for information on new vulnerabilities may need to make some adjustments. CISA said it will continue to provide risk-focused vulnerability information through its KEV catalog, alerts, and advisories. Related: CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks Related: CISA Warns of Exploited Gitea Vulnerability Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsPixel Modem Zero-Day Exploited in Targeted AttacksUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance MalwareEnterprises Warned of Attacks Exploiting WSO2 VulnerabilityTexas Utility CenterPoint Energy Confirms Breach After Hacker Leaks DataOpenAI Investigates Report Linking AI Agents to RubyGems AttackMicrosoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Latest News Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsOpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityISC Patches 14 Vulnerabilities in BIND 9 Security UpdateRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardCISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the Moveincident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F04\u002FCISA-Cybersecurity.jpg","2026-09-17T14:28:00+00:00","2026-09-17T18:00:28.532567+00:00",7,[18,21,24],{"name":19,"type":20},"Known Exploited Vulnerabilities catalog","product",{"name":22,"type":23},"CVSS","technology",{"name":25,"type":20},"weekly vulnerability bulletin","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":26,"icon":28,"name":29,"slug":30},null,"Policy","policy",[32,37,39],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"217d3263-c763-41ca-875e-06901f522fe0","NIST","nist",{"category":38},{"id":26,"icon":28,"name":29,"slug":30},{"category":40},{"id":41,"icon":28,"name":42,"slug":43},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]