CISA Is Scrapping Its Weekly Vulnerability Bulletin

The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
A wide 16:9 photograph of an empty government briefing room at dusk, shot from a low angle looking toward a large projection screen that glows a faint blue-whit
Share

Key points

  • CISA will stop publishing its weekly vulnerability bulletin on 28 September 2025, ending a longstanding digest aimed at federal security teams.
  • The retirement is tied directly to Binding Operational Directive 26-04, which orders US civilian federal agencies to prioritise patches based on evidence of active exploitation rather than numerical severity scores.
  • BOD 26-04 applies only to Federal Civilian Executive Branch systems; it does not cover national security systems or intelligence community networks.
  • CISA says it will continue publishing through its Known Exploited Vulnerabilities catalogue, its Cybersecurity Alerts and Advisories feed, and the Common Vulnerabilities and Exposures database.
  • The agency is also pushing vendors and chief information security officers to rely on suppliers' own security bulletins rather than waiting for a government digest.

For years, CISA sent federal security teams a regular bulletin listing the software flaws they should worry about that week. That stops on 28 September.

The reason is Binding Operational Directive 26-04, or BOD 26-04. A Binding Operational Directive is a compulsory order from the Department of Homeland Security that civilian federal agencies must follow by law. Think of it as a standing rule book that every government department has to obey when handling its IT systems.

What does the new directive actually change?

BOD 26-04 tells agencies to stop ranking which patches matter most by a vulnerability's CVSS score, a numbered rating of how dangerous a flaw looks on paper, and start ranking them by whether criminals are actively exploiting the flaw in the real world. Evidence of exploitation counts for more than a theoretical danger score.

The logic is sound. A flaw with a high score that nobody is using to attack anyone is less urgent than a lower-rated one that criminals already baked into their attack kits last Tuesday. The weekly bulletin was built around the old model. CISA says the new one makes it redundant.

What the directive does not say is why both things couldn't run in parallel. CSO Online, which first flagged the retirement, noted the same gap. CISA has not offered a public explanation for the either-or choice.

What does CISA still publish?

Three channels stay live after 28 September.

Channel What it covers
Known Exploited Vulnerabilities (KEV) catalogue Flaws confirmed as actively exploited; agencies must patch these by set deadlines
Cybersecurity Alerts and Advisories Urgent notices about active campaigns and critical threats
Common Vulnerabilities and Exposures (CVE) database The master list of publicly known software flaws, each assigned a unique CVE identifier

CISA is also telling chief information security officers, the executives responsible for an organisation's security posture, to track vendors' own patch notices directly rather than waiting for a government digest to curate them.

This is the seventh piece we've filed on BOD 26-04, and yesterday's story on the Linux kernel KEV additions showed the directive already producing real patch deadlines. The bulletin retirement is the other side of that coin: the agency is pruning scheduled output and betting that live threat signals do the job better.

Earlier this month CISA issued a warning about criminals using AI-generated tools to build and launch attacks. The agency hasn't publicly linked that problem to the bulletin retirement, though both moves point the same direction: output tied to real-world evidence rather than a publishing schedule.

For ordinary federal employees, the practical change is invisible. Agency security teams lose a familiar weekly reference point and gain an instruction to move faster when exploitation evidence appears.

Should you worry?

Private-sector organisations aren't bound by BOD 26-04. The principle still holds: a patch addressing a flaw that criminals are already using deserves to jump the queue, whatever score it carries on a spreadsheet.

© 2026 Threat Vectr