CISA retires Weekly Vulnerability Bulletin; points defenders to KEV / BOD 26-04 risk-based patching
SecurityWeek (17 September 2026) reports that CISA has discontinued its Weekly Vulnerability Bulletin — the alphabetical product dump of newly recorded CVEs with severity/CVSS/patch fields but no exploitation context. CISA framed the change as aligning with Binding Operational Directive (BOD) 26-04 (June), which directs US federal agencies to prioritise remediation using real-world risk factors including evidence of exploitation and exposure, not severity scores alone. CISA continues risk-focused output via the Known Exploited Vulnerabilities (KEV) catalog, alerts, and advisories. Practical takeaway for AU SOCs that mirrored the bulletin: shift intake to KEV plus vendor PSIRTs / NVD / ASD-ACSC alerts rather than expecting a CISA weekly CVE dump. Wire-primary (SecurityWeek) this pass; CISA search did not surface a matching gov landing URL during the fetch.
- Product
- CISA vulnerability publications (Weekly Vulnerability Bulletin retired)
- Versions
- n/a
- Exploited in Australia?
- no
- Patch to
- Update vuln-management runbooks: drop dependency on CISA weekly bulletin; prioritise KEV + exploited-first triage (see CyberStack critical-advisory-intake).
Primary: SecurityWeek — CISA retires Weekly Vulnerability Bulletin (17 Sep 2026) · Vendor: CISA — Known Exploited Vulnerabilities (KEV) catalog
