CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CISA decides weekly vulnerability bulletin isn't necessary anymore

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7574

As cited

Copy frozen at (site build).

vulnerabilities

CISA decides weekly vulnerability bulletin isn't necessary anymore

The Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin on September 28, 2026, shifting to a risk-based approach rather than severity-based prioritization for federal agencies. The agency directs users to monitor its known exploited vulnerabilities catalog, cybersecurity alerts, and advisories instead. The move reflects CISA's June Binding Operational Directive that prioritizes vulnerabilities based on real-world exploitation risk and automation potential rather than static Common Vulnerability Scoring System (CVSS) scores alone.

Why it matters: Federal security teams and practitioners relying on CISA's weekly bulletin must immediately switch to the KEV catalog and cybersecurity advisories subscriptions in GovDelivery or Granicus to avoid missing critical vulnerability notifications after September 28.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary