CISA said on Wednesday it will stop its weekly vulnerability bulletin at the end of September and replace the CVSS-ranked format with a risk-based prioritization model. The change shifts the agency away from a simple severity list and toward guidance that adds context to remediation decisions.
Under the old bulletin, vulnerabilities were sorted mainly by Common Vulnerability Scoring System (CVSS) severity. The new model is meant to weigh whether a weakness is actually exposed, being used, or matters to the business, so a higher score will no longer automatically mean a higher-place patch.
For federal agencies and contractors that have mirrored CISA’s weekly list, the practical shift is in triage: score alone will matter less than the surrounding risk picture. That changes how patch queues are ranked even when the underlying vulnerability landscape has not changed.