CISA to Retire Weekly Vulnerability Bulletin as It Shifts to Risk-Based Approach
The US Cybersecurity and Infrastructure Security Agency (CISA) has announced it will stop publishing its long-running weekly vulnerability bulletin from Monday, September 28. The agency says the change reflects its move away from static severity scoring (such as CVSS) towards a more risk-based approach to managing vulnerabilities.
This shift builds on a Binding Operational Directive issued in June, which instructs covered US federal agencies to prioritise vulnerabilities based on real-world risk factors such as evidence of active exploitation, the level of system access a flaw could grant, and whether exploitation can be automated, rather than treating all vulnerabilities and systems as equally important.
CISA has not explained why it chose to scrap the bulletin entirely rather than update its format to match the new approach. One possible factor is the sheer volume of vulnerabilities now being disclosed, driven partly by AI-assisted security research, alongside backlogs in vulnerability databases and growing numbers of low-quality or AI-generated vulnerability reports that make simple weekly lists harder to maintain.