The Cybersecurity and Infrastructure Security Agency (CISA) will stop publishing weekly roundups of newly disclosed software vulnerabilities at the end of September, the agency announced on Thursday.
CISA is ending its Vulnerability Bulletin “as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach,” the agency said in a statement.
The weekly bulletins, published since early 2004, listed vulnerabilities published during the reporting period along with their CVEs, severity scores and brief descriptions.
As vulnerabilities swamp defenders in the AI era, CISA has shifted to a risk-based approach to vulnerability management. In July, the agency issued new vulnerability remediation guidelines to other agencies that set deadlines based on several criteria, including whether targeted assets are internet-accessible and whether exploitation can be automated. While the guidelines are binding only on federal agencies, CISA has urged non-government organizations to follow the same approach by evaluating their unique risk exposure when making remediation decisions.
“Not all vulnerabilities matter,” Lindsey Cerkovnik, CISA’s branch chief for vulnerability response and coordination, said at the DEF CON hacker conference in August. “Not all vulnerabilities that do matter matter at the same level for you and your organization.”
CISA said in its Thursday statement that sunsetting the bulletin aligns with the prioritization directive it issued in July, “which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.”
As it discourages organizations from relying solely on Common Vulnerability Scoring System (CVSS) scores to decide which vulnerabilities to fix, CISA has also been highlighting the Stakeholder-Specific Vulnerability Categorization (SSVC) system as a more nuanced approach to vulnerability analysis.
Chris Butera, CISA’s acting executive assistant director for cybersecurity, said on Wednesday at Google’s Cyber Defense Summit that the agency has been discussing SSVC with companies that sell vulnerability management software. “They’re building some of this prioritization into their vulnerability tooling,” Butera said.
Although it is discontinuing the weekly vulnerability roundups, CISA will continue issuing advisories about specific vulnerabilities and adding them to its Known Exploited Vulnerabilities catalog. One of the criteria in the agency’s recent prioritization guidelines is whether a vulnerability has been listed in that catalog.