Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US approves visas for top Iranian leaders to attend UN General Assembly | United Nations News

    September 17, 2026

    Romanian president taps EU lawmaker Mureșan to lead country out of crisis – POLITICO

    September 17, 2026

    UK Youth Parliament looks set to be axed

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US approves visas for top Iranian leaders to attend UN General Assembly | United Nations News
    • Romanian president taps EU lawmaker Mureșan to lead country out of crisis – POLITICO
    • UK Youth Parliament looks set to be axed
    • The fix for rogue AI agents could be more AI
    • Anthropic Launches Claude Code Projects in Beta: Parallel Cloud Sessions That Keep Running After You Close Your Laptop
    • CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
    • Bitcoin Price Unlikely To Be Bothered By Interest Rate Hike: Grayscale
    • NASA Awards Launch Services for StarBurst Gamma-Ray Detector
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 17, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The US Cybersecurity and Infrastructure Security Agency (CISA) announced on Wednesday that it’s retiring its weekly vulnerability bulletin.

    The vulnerability bulletin will be discontinued on September 28 as part of a shift to a risk-based approach in vulnerability management. 

    The bulletin provides a summary of new vulnerabilities recorded each week. It includes information such as product name, description of the flaw, the date of publication, severity, CVSS score, CVE identifier, and patch information (when available).

    Each bulletin contains entries for thousands of vulnerabilities, sorted alphabetically by affected product name and severity, but it does not provide guidance on prioritizing the security holes. Without threat intelligence or context on active exploitation, the sheer volume of flaws can lead to alert fatigue for defenders.

    CISA noted that the discontinuation of the bulletin “aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.”

    BOD 26‑04, published in June, required federal agencies to review and update their vulnerability management policies and prioritize the remediation of flaws included in the KEV catalog.

    Advertisement. Scroll to continue reading.

    In recent years there has been a broad industry transition away from relying solely on CVSS metrics. While CVSS measures theoretical technical severity, modern risk-based vulnerability management frameworks prioritize active exploits, threat actor interest, and exposure level.

    Since its introduction in 2021, CISA’s Known Exploited Vulnerabilities (KEV) catalog has largely eclipsed generic vulnerability summaries as the primary reference point for defenders. By focusing strictly on bugs with documented in-the-wild exploitation, the KEV list provides actionable prioritization that static weekly bulletins could not match.

    However, with the weekly bulletin gone, security operations centers (SOCs) that have relied on it for information on new vulnerabilities may need to make some adjustments. 

    CISA said it will continue to provide risk-focused vulnerability information through its KEV catalog, alerts, and advisories. 

    Related: CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

    Related: CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

    Related: CISA Warns of Exploited Gitea Vulnerability

    Bulletin CISA pivot retires Riskbased Vulnerability Weekly
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI details more cases of AI agents taking unauthorized actions

    OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

    Brevo supply-chain attack injected ClickFix scripts on customer sites

    Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

    OpenAI admits six new misalignment incidents under new reporting framework

    Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US approves visas for top Iranian leaders to attend UN General Assembly | United Nations News

    September 17, 2026

    Romanian president taps EU lawmaker Mureșan to lead country out of crisis – POLITICO

    September 17, 2026

    UK Youth Parliament looks set to be axed

    September 17, 2026

    The fix for rogue AI agents could be more AI

    September 17, 2026
    Latest Posts

    ADNOC, SLB roll out AI-powered tool across over 120 rigs to enhance drilling ops

    August 4, 2026

    Mining threat persists in Raja Ampat, Indonesia’s ‘Amazon of the Seas’

    August 4, 2026

    Smoke Streams Across Eastern Washington

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US approves visas for top Iranian leaders to attend UN General Assembly | United Nations News

    September 17, 2026

    Romanian president taps EU lawmaker Mureșan to lead country out of crisis – POLITICO

    September 17, 2026

    UK Youth Parliament looks set to be axed

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.