09/16/2026 1:00 PM EST

On September 28, CISA will discontinue the weekly Vulnerability Bulletin as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach. This change aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.
CISA will continue to provide risk-focused vulnerability information through:
- CISA’s Known Exploited Vulnerabilities (KEV) Catalog
- CISA Cybersecurity Alerts and Advisories
- CVE: Common Vulnerabilities and Exposures
Current Vulnerability Bulletin email subscribers should update their GovDelivery/Granicus preferences by selecting Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories subscription topics to continue receiving related updates.
CISA also encourages organizations to consult vendor and provider advisories directly, as appropriate, to support their internal vulnerability management processes.
This change only affects current Vulnerability Bulletin email subscribers, along with security teams, critical infrastructure owners and operators, state, local, tribal, and territorial partners, and other stakeholders that have relied on weekly CVSS‑based summaries. CISA remains committed to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk.
Discover more from #News247WorldPress
Subscribe to get the latest posts sent to your email.

