Vulnerabilities · 3 days ago
CISA said on Wednesday it will stop its weekly vulnerability bulletin at the end of September and replace the CVSS-ranked format with a risk-based prioritization model. The change shifts the agency away from a simple severity list and toward guidance that adds context to remediation decisions.
Under the old bulletin, vulnerabilities were sorted mainly by Common Vulnerability Scoring System (CVSS) severity. The new model is meant to weigh whether a weakness is actually exposed, being used, or matters to the business, so a higher score will no longer automatically mean a higher-place patch.
For federal agencies and contractors that have mirrored CISA’s weekly list, the practical shift is in triage: score alone will matter less than the surrounding risk picture. That changes how patch queues are ranked even when the underlying vulnerability landscape has not changed.
5 sources covering this story
CISA is ending its monthly vulnerability bulletin
Does its claim of conforming to BOD requirements ring true?
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
CISA decides weekly vulnerability bulletin isn't necessary anymore
Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
Part of the PlainSec briefing for 2026-09-19