CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026

Cybersecurity and Infrastructure Security Agency (CISA)

You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available.

CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026
09/16/2026 1:00 PM EST

On September 28, CISA will discontinue the weekly Vulnerability Bulletin as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach. This change aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.

CISA will continue to provide risk-focused vulnerability information through:

Current Vulnerability Bulletin email subscribers should update their GovDelivery/Granicus preferences by selecting Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories subscription topics to continue receiving related updates.

CISA also encourages organizations to consult vendor and provider advisories directly, as appropriate, to support their internal vulnerability management processes.

This change only affects current Vulnerability Bulletin email subscribers, along with security teams, critical infrastructure owners and operators, state, local, tribal, and territorial partners, and other stakeholders that have relied on weekly CVSS‑based summaries. CISA remains committed to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk.