CISA Is Killing Its Weekly Vulnerability Bulletin, and Your Patch Process Should Change With It
Cybersecurity

CISA Is Killing Its Weekly Vulnerability Bulletin, and Your Patch Process Should Change With It

The agency will stop publishing its weekly CVE roundup on September 28 and push federal agencies toward risk-based prioritization instead of blanket CVSS scoring, a shift every enterprise patch program should copy.

PublishedSeptember 21, 2026
Read time5 min read
Share

What CISA announced

The Cybersecurity and Infrastructure Security Agency said on Wednesday, September 16, that it will discontinue its weekly vulnerability bulletin effective September 28, 2026. The bulletin has for years been a standard reference for security teams tracking newly disclosed CVEs across vendors, summarized in a single weekly digest. CISA framed the change as a shift to what it called a modern, risk-based approach to vulnerability management, one that weighs evidence of real-world exploitation over static severity scores.

The change formalizes a June directive, Binding Operational Directive BOD-26-04, that already requires federal civilian executive branch agencies to prioritize remediation based on evidence of exposure or exploitation, the degree of control an exploit grants an attacker, and whether exploitation can be automated at scale. CISA said it remains committed to strengthening national cyber defense and will point users toward its Known Exploited Vulnerabilities catalog, ongoing cybersecurity advisories, and the CVE catalog itself as the primary tracking resources going forward.

Why it lands now

This lands at a moment when the sheer volume of disclosed vulnerabilities has outpaced the capacity of any team, human or automated, to triage every CVE with equal attention. CISA's own framing points to AI-assisted security research as a contributing factor: as tools that automate vulnerability discovery proliferate on both the defensive and offensive sides, the raw count of published CVEs keeps climbing, while the National Vulnerability Database has struggled with enrichment backlogs that leave many entries without the contextual scoring data teams rely on.

A blanket weekly bulletin built for a world of hundreds of new CVEs a month makes less sense in a world producing thousands, and CISA's answer, lean harder on the Known Exploited Vulnerabilities catalog and directive-driven risk scoring, reflects where most mature enterprise vulnerability management programs have already been heading. The federal government formally catching up to that practice removes a middle-ground reference point that many teams used to justify a hybrid approach between pure CVSS and pure exploitation-based triage.

The end of CVSS as a sufficient signal

CVSS scores measure theoretical severity, how bad an exploit could be under ideal attacker conditions, not the likelihood that a given vulnerability will actually be weaponized against a given organization. Security teams have known this for years, but the weekly bulletin's format implicitly reinforced score-based triage by presenting new CVEs in a flat list without strong signals about which ones mattered most right now. Its removal forces a cleaner break: teams that have been leaning on CVSS as their primary or sole prioritization input now have one less structural nudge toward that habit and no federal reference model normalizing it.

The KEV catalog, by contrast, only lists vulnerabilities CISA has confirmed are being actively exploited, a much smaller and more actionable list than the full CVE firehose. Enterprises that have not already built a patch prioritization workflow anchored to KEV additions, supplemented by threat intelligence on exploitation in their specific sector, should treat this bulletin discontinuation as the forcing function to build one now, rather than reactively scrambling once the weekly digest stops landing in inboxes on September 28.

What this means for vulnerability management budgets

Risk-based prioritization sounds sensible in principle and is genuinely harder to execute than CVSS-based triage in practice, because it requires threat intelligence feeds, exploitation telemetry, and asset context that many mid-sized security teams have not invested in building. A CVSS score is free and universal, exploitation evidence requires either a paid threat intelligence subscription, participation in information sharing communities, or in-house research capacity that smaller teams rarely have budget for.

CISOs should read this shift as validation for budget requests around threat intelligence tooling and exposure management platforms that correlate CVE data with active exploitation signals and asset criticality. The federal government moving away from a flat severity model is a useful data point in any board conversation about why vulnerability management spend needs to grow beyond a scanner and a spreadsheet, toward tooling that can actually answer the question CVSS alone cannot: is this specific vulnerability, on this specific asset, being exploited right now.

What replaces the bulletin in practice

For federal agencies bound by BOD-26-04, the KEV catalog effectively becomes the mandatory patch list, since the directive requires remediation based on exploitation evidence rather than blanket coverage of every disclosed CVE. Private sector security teams operate outside that directive, yet many already voluntarily align their SLAs to KEV additions because it is the most reliable public signal of what attackers are actually using, updated continuously rather than batched into a weekly summary.

The practical gap teams need to fill is monitoring cadence. A weekly bulletin, however imperfect, gave teams a scheduled checkpoint to review new disclosures across every vendor in one place, which made it easy to build a habit around even if the underlying prioritization logic was weak. Without it, teams need either an automated feed subscription to KEV catalog updates and CISA advisories or a defined internal cadence, ideally daily rather than weekly given how fast KEV additions can translate into active exploitation, to make sure nothing slips through during the transition and beyond it.

What this means for your roadmap

Before September 28, audit whatever process currently consumes CISA's weekly bulletin and confirm it has a replacement data feed lined up, whether that is a direct KEV catalog API integration, a threat intelligence vendor that ingests CISA advisories automatically, or a defined internal owner checking the CVE catalog on a set schedule. Teams that let this transition happen passively will have a visibility gap precisely when vulnerability volume is climbing fastest.

More strategically, use this policy shift as the opening to formalize exploitation-evidence-based prioritization as your organization's stated patch management standard, not just an informal practice some analysts already follow. Document it, tie SLAs to KEV catalog status rather than CVSS score alone, and bring the federal directive into your next audit or compliance conversation as external validation for a change your team may have wanted to make for years but lacked the reference point to justify.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#vulnerability-management#patch-management#kev-catalog#cve-prioritization#cvss-scoring#federal-agencies#risk-based-security#vulnerability-disclosure#enterprise-patch-strategy