CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus

The US Cybersecurity and Infrastructure Security Agency (CISA) has made a significant shift in its approach to vulnerability management. Effective September 28, CISA will discontinue its weekly vulnerability bulletins, instead opting for a risk-based focus on prioritizing vulnerabilities that pose a real-world threat.

This move is consistent with CISA’s advice that organizations prioritize vulnerabilities based on their actual risk to the organization, rather than solely relying on Common Vulnerability Scoring System (CVSS) scores. In recent months, vulnerability disclosures have surged due in part to the increasing use of AI-powered tools by attackers and defenders alike. Microsoft, for instance, disclosed close to 1,000 vulnerabilities in its most recent monthly security update, a volume that far exceeds typical totals.

CISA’s decision is a response to the growing backlog of vulnerabilities facing organizations. With more than 70,000 known vulnerabilities listed on CVE.org, relying solely on CVSS scores can be misleading and ineffective. “A severity score alone cannot tell an organization what to patch first,” says Kevin Surace, CEO of TokenCore. In fact, CISA’s own analysis of vulnerability data from 2024 and 2025 showed that despite a surge in vulnerability volume, the number of vulnerabilities exploited by attackers grew only marginally.

This trend is not surprising, given that attackers tend to focus on a small subset of all vulnerabilities. Waseem Ahmed, founding member and head of engineering at Secure.com, notes that many organizations continue to rely heavily on severity scores without enough visibility into how vulnerabilities connect to real attack paths. “The goal isn’t to eliminate every vulnerability, but to ensure the most critical risks are addressed before attackers can exploit them,” he says.

CISA’s shift towards a risk-based focus is a welcome development in the cybersecurity community. By emphasizing the need for organizations to consider factors such as exploit automation, technical impact, asset exposure, and KEV status, CISA is encouraging a more nuanced approach to vulnerability management.

So what does this mean for organizations? In practical terms, it means that security teams will need to be more proactive in assessing vulnerabilities and prioritizing remediation based on actual risk. This may involve using tools such as the CISA Known Exploited Vulnerability (KEV) Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts to inform decision-making.

Ultimately, the shift towards a risk-based focus is a necessary response to the evolving threat landscape. As AI-powered attacks become increasingly common, it’s essential that organizations prioritize vulnerabilities based on real-world risk rather than relying solely on severity scores. By doing so, they can significantly reduce their exposure to cyber threats and stay ahead of emerging risks.


Source: Dark Reading — 2026-09-17