Full Report
Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
Analysis Summary
# Industry News: CISA Retires Weekly Vulnerability Bulletin in Shift to Risk-Based Prioritization
## Summary
The Cybersecurity and Infrastructure Security Agency (CISA) has announced the discontinuation of its long-standing weekly vulnerability bulletin, effective September 28. The move marks a definitive pivot away from static severity scores (CVSS) toward a dynamic, risk-based approach focused on real-world exploitation.
## Key Details
- **Date:** Announced September 16, 2026 (Effective September 28, 2026)
- **Companies Involved:** CISA (Cybersecurity and Infrastructure Security Agency)
- **Category:** Regulatory/Government Policy Update
## The Story
For years, CISA’s weekly bulletin served as a consolidated list of newly identified vulnerabilities. However, CISA is retiring this format in alignment with **Binding Operational Directive (BOD) 26-04**. This directive mandates that federal agencies move beyond treating all "High" or "Critical" CVSS scores equally. Instead, CISA is pushing for a remediation strategy based on the **Known Exploited Vulnerabilities (KEV)** catalog.
The agency argues that a static list of CVEs (Common Vulnerabilities and Exposures) is no longer sufficient in an era where AI-assisted research has flooded the market with discoveries, often creating a "signal-to-noise" problem. The new paradigm focuses on three pillars: evidence of actual exploitation, the degree of control an attacker gains, and the ease of automation for the exploit.
## Business Impact
### For the Companies Involved
- **CISA:** Reduces administrative overhead of maintaining a static list that often lagged behind real-time threats; reaffirms its role as a strategic risk advisor rather than a mere data aggregator.
### For Competitors (Commercial VDR Vendors)
- **Vulnerability Management Providers:** Companies like Qualys, Tenable, and Rapid7 may see increased demand for their proprietary "risk scoring" engines as the government officially moves away from simple CVSS-based compliance.
### For Customers (Federal Agencies & Private Sector)
- **End Users:** Organizations relying on the bulletin for manual patch management must now pivot to automated feeds or CISA’s KEV catalog. Failure to update subscription settings in GovDelivery could lead to missed critical alerts.
### For the Market
- **Standardization Shift:** This move accelerates the industry-wide transition from "Vulnerability Management" to "Exposure Management," where business context dictates the urgency of a patch.
## Technical Implications
The shift highlights the diminishing utility of the **Common Vulnerability Scoring System (CVSS)** in isolation. While CVSS measures technical severity, CISA’s new approach emphasizes **EPSS (Exploit Prediction Scoring System)** principles—prioritizing bugs that are actually being weaponized in the wild.
## Strategic Analysis
- **Market Positioning:** CISA is positioning itself as a proactive threat-intelligence lead rather than a library of record.
- **Competitive Advantage:** By focusing on the KEV catalog, CISA provides a high-fidelity list that helps resource-strapped IT teams focus on the 4% of vulnerabilities that actually pose a threat.
- **Challenges:** The National Vulnerability Database (NVD) backlog remains a concern; if the broader CVE ecosystem is struggling, CISA’s reliance on KEV puts immense pressure on their ability to identify exploits quickly.
## Industry Reactions
- **Analyst Opinions:** Most analysts view this as a necessary evolution, noting that the sheer volume of CVEs has made "weekly summaries" obsolete for modern SOCs.
- **Market Response:** There is some concern regarding "information gaps" for smaller organizations that lack the tools to ingest more complex, real-time risk feeds.
## Future Outlook
- **Predictions:** Expect more government agencies globally to adopt "Risk-Based Vulnerability Management" (RBVM) as the standard, potentially leading to the retirement of other legacy static reporting formats.
- **What to watch for:** Whether CISA introduces a more interactive, API-driven replacement for the bulletin that aligns with BOD 26-04.
## For Security Professionals
Practitioners must immediately ensure they are subscribed to **CISA’s KEV Catalog alerts** and **Cybersecurity Advisories**. If your current patch management policy is "Patch all CVSS 7.0+ within 30 days," it is time to rewrite that policy to prioritize **Exploited** vulnerabilities regardless of their base score.