Skip to content

CISA shuts down its weekly vulnerability bulletin today

The agency is retiring the long-running Vulnerability Summary Bulletin on 28 September, pointing subscribers to the KEV catalogue, its advisories, and CVE.org instead.

Source: CISA

CISA discontinued its weekly Vulnerability Bulletin today, 28 September, the digest that has rounded up newly recorded CVEs every week for years. The agency says it is moving “from severity-based vulnerability management to a modern, risk-based approach”, in line with Binding Operational Directive 26-04, which replaces severity scores alone with real-world risk factors as the basis for prioritising fixes.

CISA is pointing subscribers to three places instead: the Known Exploited Vulnerabilities catalogue, its Cybersecurity Alerts and Advisories, and CVE.org. Anyone who gets vulnerability data by email through GovDelivery needs to update their subscription preferences to keep receiving updates through those channels, and CISA is telling organisations to also watch vendor advisories directly rather than relying on a single federal digest.

Why it matters: if you or your team built any tooling, alerting or a weekly review process around that bulletin feed, it goes quiet today with nothing dropped in its place automatically. The KEV catalogue is a better signal for what to patch first anyway, since it only lists flaws with confirmed exploitation, but it is a different feed with a different shape, so anything parsing the old bulletin format needs updating, not just re-pointing.

The caveat: the bulletin only ever listed newly recorded CVEs, not exploitation status, so its loss is mostly a workflow disruption rather than a loss of security signal.

Share

More from The Wire

All briefs