The US Cybersecurity and Infrastructure Security Agency (CISA) has announced it will discontinue its weekly vulnerability bulletins as of September 28. This move marks a significant shift in CISA’s approach to cybersecurity, one that prioritizes risk-based vulnerability management over traditional severity-based approaches.
For years, CISA had been releasing weekly vulnerability bulletins, which listed newly disclosed vulnerabilities along with their Common Vulnerability Scoring System (CVSS) scores. These scores aimed to provide a standardized way of measuring the severity of each vulnerability. However, as the number of disclosed vulnerabilities has skyrocketed in recent months – Microsoft alone reported nearly 1,000 vulnerabilities in its most recent monthly security update – organizations have struggled to keep up with the demand for remediation.
CISA’s decision is consistent with its broader advice that organizations should prioritize vulnerabilities based on real-world risk rather than relying solely on CVSS scores. This approach acknowledges that attackers typically focus on a small subset of all vulnerabilities, making it essential for organizations to identify and address those critical risks first.
Hom Bahmanyar, global enablement officer at Ridge Security Technology Inc., welcomes CISA’s emphasis on risk-based vulnerability prioritization. “Organizations that rely primarily on CVSS severity scores often miss the broader risk context that should drive remediation decisions,” he notes. By considering factors like exploit automation, technical impact, asset exposure, and Known Exploited Vulnerability (KEV) status, organizations can make more informed decisions about which vulnerabilities to address.
The move away from traditional vulnerability management approaches is also driven by the growing use of AI in cybersecurity. As attackers increasingly leverage AI to automate attacks at greater scale and speed, CISA’s focus on contextual, risk-based vulnerability prioritization provides a much-needed update to the agency’s approach.
Waseem Ahmed, founding member and head of engineering at Secure.com, emphasizes that organizations should not aim to eliminate every vulnerability but instead prioritize addressing critical risks before attackers can exploit them. “In a threat landscape driven by speed, scale, and AI, context is what makes vulnerability management truly effective,” he stresses.
While CISA’s decision may be seen as a sudden shift for some organizations, it marks an important step towards more effective cybersecurity practices. By prioritizing risk-based vulnerability management, organizations can reduce their exposure to attack and focus on addressing the most critical vulnerabilities first.
Source: Dark Reading — 2026-09-17