CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The CISA is ending its weekly vulnerability bulletins, shifting to a risk-based approach to vulnerability management. This change is driven by the observation that attackers primarily exploit a small subset of vulnerabilities, despite a significant increase in the overall number of disclosed vulnerabilities. CISA encourages organizations to prioritize vulnerabilities based on exploitability and real-world risk, rather than solely relying on CVSS scores. This move is intended to alleviate the pressure on security teams and improve overall risk mitigation in a rapidly evolving threat landscape.
The US Cybersecurity and Infrastructure Security Agency (CISA) has decided to discontinue its weekly vulnerability bulletins, effective Sept. 28. This shift reflects a broader strategy to move organizations away from a severity-based vulnerability management system to one focused on risk prioritization. The agency has observed that despite a surge in the number of vulnerabilities disclosed, the number of vulnerabilities actually exploited by attackers has remained relatively stable over the past two years.
CISA’s decision is consistent with its advice that organizations consider exploit automation, technical impact, asset exposure, and KEV status when prioritizing remediation efforts. The agency emphasizes that relying solely on CVSS scores can be misleading, as many organizations struggle to keep pace with the growing volume of vulnerabilities.
“Newly recorded vulnerabilities will remain available on CVE.org,” CISA stated, “and users should rely on CISA’s Known Exploited Vulnerability (KEV) Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts for actionable, risk‑based updates.”
According to Waseem Ahmed, founding member and head of engineering at Secure.com, “The goal isn’t to eliminate every vulnerability, but to ensure the most critical risks are addressed before attackers can exploit them.”
Kevin Surace, CEO of TokenCore, expressed concern about the change, stating that the weekly bulletin provided a dependable resource for security teams. He notes that removing this resource shifts the responsibility of assembling a comprehensive view of vulnerabilities onto already strained security teams, particularly at smaller organizations. CISA’s move is intended to address the challenges of a threat landscape increasingly driven by speed, scale, and AI.
