As cited
Copy frozen at (site build).
vulnerabilities
CISA decides weekly vulnerability bulletin isn't necessary anymore
The Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin on September 28, 2026, shifting to a risk-based approach rather than severity-based prioritization for federal agencies. The agency directs users to monitor its known exploited vulnerabilities catalog, cybersecurity alerts, and advisories instead. The move reflects CISA's June Binding Operational Directive that prioritizes vulnerabilities based on real-world exploitation risk and automation potential rather than static Common Vulnerability Scoring System (CVSS) scores alone.
Why it matters: Federal security teams and practitioners relying on CISA's weekly bulletin must immediately switch to the KEV catalog and cybersecurity advisories subscriptions in GovDelivery or Granicus to avoid missing critical vulnerability notifications after September 28.
- Source published
- First seen by Cybersecurity Tracker