CISA said its weekly vulnerability bulletin will stop going out on Monday, September 28, a move the agency ties to a shift from severity-based listings toward “a modern, risk-based approach.”
September 28: CISA ends the weekly vulnerability bulletin
The Cybersecurity and Infrastructure Security Agency announced the discontinuation of its long-running weekly vulnerability bulletin effective Monday, September 28. The agency framed the change as part of a deliberate move away from managing vulnerabilities by static severity alone and toward prioritization guided by real-world risk. The announcement did not explain why CISA chose to retire the bulletin rather than adapt it to the new framework.
The June Binding Operational Directive and “a modern, risk-based approach”
CISA points to a June Binding Operational Directive (BOD) as the architecture behind the change. According to the agency, the BOD directs covered federal civilian agencies to prioritize security updates based on “real-world risk rather than treating all vulnerabilities and systems equally.” The BOD, CISA said, “evolves upon CISA’s known exploited vulnerabilities catalog and increases mission readiness across the federal government by efficiently prioritizing high-risk vulnerabilities for timely action, while deferring action against low-risk vulnerabilities.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow CISA now defines what counts as high risk
The June announcement includes a remediation table that expands decision criteria beyond static CVSS scores. CISA identifies several concrete factors that go into determining severity: evidence of exposure and exploitation; the degree of control granted by exploitation; and whether exploitation can be automated. The BOD therefore guides agencies to consider exploitation activity and impact characteristics — not only numerical scores — when deciding which vulnerabilities require immediate action.
Where CISA wants subscribers to go instead: KEV Catalog, Cybersecurity Advisories, and the CVE catalog
CISA told current bulletin recipients that, moving forward, they should rely on the agency’s known exploited vulnerabilities (KEV) catalog, its cybersecurity alerts and advisories, and the CVE catalog to stay up to date. The agency warned that anyone who currently receives and relies on the weekly bulletin needs to log into their GovDelivery or Granicus account and ensure the KEV Catalog and Cybersecurity Advisories subscriptions are enabled; otherwise, “critical notices could be missed,” the announcement warned.
CISA also made clear that it does not want practitioners to abandon CVEs entirely: the agency counseled continued use of the CVE catalog alongside its own curated KEV list and advisory feed. “CISA remains committed to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk,” the agency said in its announcement.
Why CISA may have retired the bulletin: CVSS limits, AI-assisted research, and the NVD backlog
The agency did not offer a single, explicit rationale for scrapping the weekly email. The announcement and related commentary point to several operational pressures that help explain the timing. The June BOD explicitly moves covered agencies away from relying on static Common Vulnerability Scoring System (CVSS) scores alone. At the same time, patches now often address rapidly growing numbers of vulnerabilities each cycle due in part to AI-assisted security research, and the National Vulnerability Database (NVD) remains under a heavy backlog. CISA also acknowledged that the broader CVE ecosystem faces an increase in bogus AI-generated reports that must be triaged to find genuine vulnerabilities. One possibility the agency flagged is simply volume: the flow of new vulnerabilities may be too large for a single weekly email to represent the targeted, risk-based prioritization the BOD requires.
What this means for federal agencies, security teams, and general subscribers
- Federal civilian agencies: Covered agencies must follow the June BOD’s direction to prioritize remediations based on the new risk criteria, using CISA’s KEV catalog and advisories rather than a weekly, severity-ranked bulletin.
- Security teams and technologists: Teams that depended on the weekly bulletin will need to enable KEV Catalog and Cybersecurity Advisories subscriptions in GovDelivery or Granicus to avoid missing critical notices; they must also adjust triage workflows to weigh exploitation evidence and impact characteristics rather than CVSS alone.
- General subscribers and administrators: Individuals who subscribed to the bulletin must take action in their GovDelivery/Granicus accounts to continue receiving targeted notices — otherwise, CISA warned, “critical notices could be missed.”
CISA’s decision closes a familiar, centralized weekly touchpoint and replaces it with a set of curated feeds and a directive that asks agencies to judge vulnerability priorities by exploitation realities rather than static scores. The agency has set the date — September 28 — and a new operational logic; what remains unanswered in the announcement is why the bulletin was retired instead of being retooled to reflect the BOD’s standards. For now, the concrete next step for those who relied on the bulletin is practical: log into GovDelivery or Granicus and subscribe to the KEV Catalog and Cybersecurity Advisories so that CISA’s chosen channels, not a discontinued weekly digest, deliver the agency’s prioritized notices.




