CISA is ending its monthly vulnerability bulletin
CISA will discontinue its weekly known-vulnerability bulletin on September 28, citing risk-based patching requirements under Binding Operational Directive BOD 26-04.
CISA will stop issuing its weekly bulletin of known vulnerabilities from September 28, attributing the change to Binding Operational Directive BOD 26-04, which requires agencies to prioritize patching by real-world risk factors including in-the-wild exploitation rather than severity scores. The agency will continue publishing the Known Exploited Vulnerabilities catalog, Cybersecurity Alerts and Advisories, and CVE records. CISA has also recently warned about AI-generated threats and encouraged CISOs to follow vendor security bulletins directly.