AI-Generated · minimax/minimax-m3

CISA will retire its weekly Vulnerability Bulletin on September 28 — and the reasoning behind it is the actual story

CISA is ending its weekly Vulnerability Bulletin at the end of September 2026, shifting from severity-based scoring toward risk-based prioritization under Binding Operational Directive 26-04.

On September 28, 2026, CISA will publish its last weekly Vulnerability Bulletin. The bulletin has catalogued newly disclosed vulnerabilities since 2004 — twenty-two years of a single weekly artifact telling security teams what had been disclosed, with a CVSS score attached — and its retirement is one of those bureaucratic decisions that looks small until you read the reasoning behind it.

The reasoning is a deliberate pivot from severity-based to risk-based vulnerability management, formalized in Binding Operational Directive 26-04. Under the old model, a vulnerability with a CVSS 9.8 and one with a CVSS 7.8 that nobody had ever exploited were treated as comparable triage items if both showed up in the same week’s feed. Under BOD 26-04, remediation is prioritized by real-world risk factors — most importantly evidence of active exploitation and exposure — which is why the Cloud Security Alliance’s CISO Daily Briefing for September 23 is now structured around what CISA added to its Known Exploited Vulnerabilities catalog and when, rather than around what scored above an arbitrary severity threshold.

That cataloguing change has real teeth. On September 18, CISA added three CVEs to the KEV with a federal remediation deadline of September 21: CVE-2025-39682, a CVSS 9.8 flaw in a TLS receive path; CVE-2026-53266, a CVSS 8.8 out-of-bounds write in netfilter/ebtables; and CVE-2025-39964, a CVSS 7.8 race condition in AF_ALG. The middle of those three is the instructive one — a 7.8 severity score would have placed it well down the old severity-ranked list, but the directive’s risk-based logic treats it as a three-day federal emergency because of what it actually does, where it actually runs, and what is actually being done with it in the wild.

Under BOD 26-04, being on the KEV with an active deadline is no longer a “patch and close the ticket” event — federal agencies are required to perform forensic triage, which is a meaningfully heavier lift than simply deploying a fix. The September 21 deadline attached to those three CVEs assumed the responder would want to know not just whether the affected systems existed in the environment, but whether they had been hit, how, and from where. That is a different job than the one the weekly Vulnerability Bulletin was built to support, and it is also a different job than the one a CVSS score alone was ever going to tell a defender to do.

There is a quiet admission baked into the move: the bulletin, in its final years, had become a feed that defenders could not realistically act on at its native cadence. A weekly list of every newly disclosed CVE, sorted by a severity metric that does not correlate cleanly with exploitation, is a feed optimised for completeness, not for triage. BOD 26-04 and the KEV-first workflow are an explicit acknowledgement that completeness and actionability pull in opposite directions at scale, and that defenders operating under federal remediation deadlines need the latter more than they need the former.

The bulletin was the right artifact for 2004, when the bottleneck in vulnerability management was knowing what had been disclosed. It is the wrong artifact for 2026, when the bottleneck is figuring out which of the things you now know about actually matter for the environment you are responsible for. CISA retiring it on September 28 is the agency admitting, in operational terms, that the centre of gravity has moved.

Sources