Somewhere, a vulnerability manager has a spreadsheet with more red cells than a crime scene wall. For years, the ritual has been familiar: sort by severity, panic politely, assign tickets, and hope the universe stops issuing CVEs for a long weekend. CISA is now retiring one of the props in that ritual. According to CISA’s GovDelivery notice, the weekly Vulnerability Bulletin will be discontinued on September 28, 2026, as the agency shifts away from severity-based vulnerability management toward risk-based prioritization.
The Bulletin Goes Quiet, According To CISA
CISA says the weekly Vulnerability Bulletin will end on September 28, 2026, as part of its move from severity-based vulnerability management to what it calls a modern risk-based approach. The agency ties the change to Binding Operational Directive 26-04, which prioritizes vulnerabilities using real-world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.
That is the important sentence, not because CVSS is useless, but because CVSS without context is basically a weather report for someone else’s building. The Register reported that CISA announced the change on Wednesday and framed it as the old format being sent out with the agency’s broader shift away from static CVSS scoring.
This is not CISA saying vulnerability disclosure no longer matters, which would be charming in the same way a smoke alarm with no battery is charming. It is saying the weekly roundup is no longer the best organizing principle for action. A list of scary numbers is not a remediation strategy.
Why Score Chasing Broke Down, According To The Register
The Register notes that Binding Operational Directive 26-04 tells covered federal civilian agencies to prioritize security updates based on real-world risk rather than treating all vulnerabilities and systems equally. That distinction is where vulnerability management stops being clerical work and starts being security engineering.
CVSS can tell you a flaw is technically severe, but it cannot tell you whether the affected system is exposed, whether anyone is exploiting the bug, or whether the vulnerable asset matters to your organization’s operations. That is how teams end up patching a dramatic high-severity flaw on a low-value internal system while an exploited vulnerability on an exposed service sits in the queue, quietly auditioning for incident response.
Threat actors, as a group, are not moved by fairness. They do not distribute attention evenly across your backlog like tiny chaotic project managers. They follow access, exploitability, exposure, and payoff.
What Replaces The Weekly Ritual, According To OffSeq
OffSeq’s Threat Radar summarizes the post-bulletin model this way: newly recorded vulnerabilities remain available through CVE.org, while users are encouraged to rely on the Known Exploited Vulnerabilities Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts for more actionable updates. In other words, the raw feed is still there, but the triage signals are expected to carry more weight.
This is the part where the security team’s morning coffee gets replaced by correlation, asset inventory, and the faint sound of someone muttering at a ticketing system. Dark Reading’s Jai Vijayan similarly reported that CISA’s move is consistent with the agency’s advice that organizations prioritize vulnerabilities that actually matter. That phrase should be printed above every patch queue.
The useful workflow is not severity alone, then panic, then heroic weekend labor. It is exposure plus exploitation evidence plus organizational impact, then remediation urgency.
What It Actually Means For You, According To Dark Reading
For security teams, the practical lesson from CISA’s shift is simple: stop treating every high-severity CVE like it has the same plot armor. Start with vulnerabilities known to be exploited, especially when affected assets are exposed. Next, weigh whether those assets support critical services, sensitive data, identity systems, or anything whose failure would make leadership discover your name. Then use severity scores as supporting evidence, not as the only judge with a tiny gavel.
That does not mean ignoring medium or high scores that lack current exploitation evidence. It means building a patching program that can explain its choices without pointing at a red cell in a spreadsheet and whispering, behold.
Keep watching how CISA operationalizes BOD 26-04, and update your vulnerability management process so it can ingest KEV entries, alerts, vendor advisories, exposure data, and asset context. The future is not fewer CVEs. The future is better triage, because the internet remains a group project and several participants are chewing on the wiring.
Sources - CISA to Sunset Weekly Vulnerability Bulletin on September 28 ...
- CISA decides weekly vulnerability bulletin isn't necessary anymore
- CISA is Sunsetting the Weekly Vulnerability Bulletin - Live Threat Intelligence - Threat Radar | OffSeq.com
- CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
Sources
- CISA decides weekly vulnerability bulletin isn't...
- CISA decides weekly vulnerability bulletin isn't necessary anymore
- CISA to Sunset Weekly Vulnerability Bulletin on September 28 ...
- How CISA BOD 26-04 changes vulnerability prioritization
- The Cyber Security Hub™'s Post
- CISA is Sunsetting the Weekly Vulnerability Bulletin - Live Threat Intelligence - Threat Radar | OffSeq.com
- CISA decides weekly vulnerability bulletin isn't necessary anymore
- CISA decides weekly vulnerability bulletin isn't...
- CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
- CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot