The U.S. Cybersecurity and Infrastructure Security Agency (CISA) will discontinue its weekly vulnerability bulletin on September 28, 2026, replacing a broad list of newly disclosed flaws with a risk-based approach to remediation. The retired bulletin did not prioritize fixes and could contribute to alert fatigue by cataloging thousands of vulnerabilities without distinguishing those posing the greatest operational threat.
The change supports Binding Operational Directive 26-04, which requires covered federal civilian agencies to weigh real-world factors such as confirmed exploitation, internet exposure, attacker control obtained through exploitation, and the potential for automated exploitation rather than relying on CVSS severity alone. CISA will continue publishing actionable vulnerability information through its Known Exploited Vulnerabilities (KEV) Catalog, cybersecurity alerts, advisories, and the CVE Catalog; existing subscribers should enable relevant GovDelivery or Granicus notifications.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA published BOD 26-04 directing covered federal civilian agencies to prioritize vulnerability remediation based on real-world risk factors, including exposure, exploitation evidence, potential control gained, and exploit automation rather than CVSS scores alone.
CISA introduced the Known Exploited Vulnerabilities (KEV) Catalog, which focuses on vulnerabilities with documented exploitation in the wild.
CISA announced it will discontinue its weekly vulnerability bulletin as part of its transition to risk-based vulnerability management. It said users should instead use the KEV Catalog, CISA alerts and advisories, and the CVE Catalog for vulnerability information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.