CISA says it will discontinue its weekly Vulnerability Bulletin at the end of fiscal year 2026, on September 28, as part of what the agency describes as “a broader shift from severity-based vulnerability management to risk-based vulnerability prioritization.” The bulletin, a standing feature of CISA’s output for years, listed newly disclosed vulnerabilities alphabetically by product and severity score without ranking them by real-world exploitation risk. CISA is directing users instead to three existing resources: newly recorded entries on CVE.org, the Known Exploited Vulnerabilities catalog, and CISA’s own Cybersecurity Alerts and Advisories alongside vendor security alerts.

The change matters because the bulletin was, for many smaller security teams without a dedicated vulnerability-management platform, the closest thing to a single feed covering everything CISA saw disclosed in a week. Removing it without a like-for-like replacement pushes those teams toward the KEV catalog by default, which is a narrower list: KEV only adds a vulnerability once CISA has evidence of active exploitation, not merely that a CVE exists. A team that relied on the bulletin as a broad early-warning net now has to actively assemble that coverage from CVE.org and vendor advisories instead of receiving it as one weekly digest.

The framing CISA gives is itself an admission about the bulletin’s failure mode: a flat, unranked list of thousands of vulnerabilities produces the alert fatigue it was meant to prevent. That argument only holds if the replacement resources are genuinely easier to triage, and KEV’s exploitation bar means a vulnerability can sit unlisted for weeks between disclosure and confirmed in-the-wild use, the exact gap CyberTech has previously found defenders underestimating. Security leaders who used the bulletin as a compliance or SLA input should confirm their vulnerability-management tooling now pulls from CVE.org and KEV directly, since nothing will forward that data to them the way the bulletin did.

CyberTech has covered how the KEV catalog itself lags real-world patch adoption in this month’s analysis of CISA’s patch deadlines, and how CISA’s forensic triage windows work in practice in its NetScaler and Fortinet advisory coverage.

Source: CISA