Advisory
Published 2026-09-17
Verified 2026-09-19

CISA retires Weekly Vulnerability Bulletin; points defenders to KEV / BOD 26-04 risk-based patching

SecurityWeek (17 September 2026) reports that CISA has discontinued its Weekly Vulnerability Bulletin — the alphabetical product dump of newly recorded CVEs with severity/CVSS/patch fields but no exploitation context. CISA framed the change as aligning with Binding Operational Directive (BOD) 26-04 (June), which directs US federal agencies to prioritise remediation using real-world risk factors including evidence of exploitation and exposure, not severity scores alone. CISA continues risk-focused output via the Known Exploited Vulnerabilities (KEV) catalog, alerts, and advisories. Practical takeaway for AU SOCs that mirrored the bulletin: shift intake to KEV plus vendor PSIRTs / NVD / ASD-ACSC alerts rather than expecting a CISA weekly CVE dump. Wire-primary (SecurityWeek) this pass; CISA search did not surface a matching gov landing URL during the fetch.

Product
CISA vulnerability publications (Weekly Vulnerability Bulletin retired)
Versions
n/a
Exploited in Australia?
no
Patch to
Update vuln-management runbooks: drop dependency on CISA weekly bulletin; prioritise KEV + exploited-first triage (see CyberStack critical-advisory-intake).

Primary: SecurityWeek — CISA retires Weekly Vulnerability Bulletin (17 Sep 2026) · Vendor: CISA — Known Exploited Vulnerabilities (KEV) catalog

tech cloud