CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
CISA will discontinue its weekly vulnerability bulletin on September 28, shifting defenders toward risk-based prioritization via the KEV catalog.
CISA announced it will retire its weekly vulnerability bulletin on September 28 as part of a shift to risk-based vulnerability management. The change aligns with Binding Operational Directive BOD 26-04, published in June, which directs federal agencies to prioritize flaws based on real-world risk factors such as exploitation evidence and to remediate KEV-listed vulnerabilities. CISA will continue providing risk-focused information through the KEV catalog, alerts, and advisories.
- Weekly bulletin ends September 28; it summarized thousands of CVEs without prioritization guidance.
- BOD 26-04 directs agencies to prioritize exploitation evidence and exposure over CVSS scores.
- KEV catalog, launched in 2021, has become defenders' primary prioritization reference.
- SOCs relying on the bulletin must adjust; CISA continues KEV, alerts, and advisories.
Full article351 words · extracted from securityweek.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) announced on Wednesday that it’s retiring its weekly vulnerability bulletin.
The vulnerability bulletin will be discontinued on September 28 as part of a shift to a risk-based approach in vulnerability management.
The bulletin provides a summary of new vulnerabilities recorded each week. It includes information such as product name, description of the flaw, the date of publication, severity, CVSS score, CVE identifier, and patch information (when available).
Each bulletin contains entries for thousands of vulnerabilities, sorted alphabetically by affected product name and severity, but it does not provide guidance on prioritizing the security holes. Without threat intelligence or context on active exploitation, the sheer volume of flaws can lead to alert fatigue for defenders.
CISA noted that the discontinuation of the bulletin “aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.”
BOD 26‑04, published in June, required federal agencies to review and update their vulnerability management policies and prioritize the remediation of flaws included in the KEV catalog.
Advertisement. Scroll to continue reading.
In recent years there has been a broad industry transition away from relying solely on CVSS metrics. While CVSS measures theoretical technical severity, modern risk-based vulnerability management frameworks prioritize active exploits, threat actor interest, and exposure level.
Since its introduction in 2021, CISA’s Known Exploited Vulnerabilities (KEV) catalog has largely eclipsed generic vulnerability summaries as the primary reference point for defenders. By focusing strictly on bugs with documented in-the-wild exploitation, the KEV list provides actionable prioritization that static weekly bulletins could not match.
However, with the weekly bulletin gone, security operations centers (SOCs) that have relied on it for information on new vulnerabilities may need to make some adjustments.
CISA said it will continue to provide risk-focused vulnerability information through its KEV catalog, alerts, and advisories.
Related: CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/cisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot/