CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026
Cybersecurity and Infrastructure Security Agency sent this bulletin at 09/16/2026 01:00 PM EDT
You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available.
On September 28, CISA will discontinue the weekly Vulnerability Bulletin as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach. This change aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.
CISA will continue to provide risk-focused vulnerability information through:
- CISA's Known Exploited Vulnerabilities (KEV) Catalog
- CISA Cybersecurity Alerts and Advisories
- CVE: Common Vulnerabilities and Exposures
Current Vulnerability Bulletin email subscribers should update their GovDelivery/Granicus preferences by selecting Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories subscription topics to continue receiving related updates.
CISA also encourages organizations to consult vendor and provider advisories directly, as appropriate, to support their internal vulnerability management processes.
This change only affects current Vulnerability Bulletin email subscribers, along with security teams, critical infrastructure owners and operators, state, local, tribal, and territorial partners, and other stakeholders that have relied on weekly CVSS‑based summaries. CISA remains committed to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk.