Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Compute & Hardware

CISA Ends Weekly Vulnerability Bulletins, Pivots to Risk-Based Focus

The agency's shift from static CVSS scores to risk-based prioritization retires the long-running weekly roundup format on September 28.

· 1 min read · 2 sources

CISA is retiring its weekly vulnerability roundup, a staple for security teams, in favor of a risk-based approach. The final bulletin will appear on September 28, after which the agency will focus on helping organizations prioritize the vulnerabilities that pose the most real-world danger rather than simply listing every disclosed flaw.

Both sources agree the decision is consistent with CISA's long-standing advice that static CVSS scores are a poor proxy for actual risk. The Register notes the shift away from the old format, while Dark Reading frames it as the agency practicing what it preaches. No source suggests the move will reduce CISA's overall vulnerability work—only that the weekly digest is no longer seen as necessary.

For infrastructure teams, the change means less noise but also less routine scanning of a fixed bulletin. The onus shifts to adopting risk-based prioritization tools and processes, which CISA has repeatedly endorsed. The agency's new focus is expected to emphasize exploitability, real-world impact, and active threats rather than raw severity numbers.

Sources · 2

  1. 01CISA Ditches Weekly Vulnerability Roundups for Risk-Based FocusDark Reading
  2. 02CISA decides weekly vulnerability bulletin isn't necessary anymoreThe Register

More in Compute & Hardware