P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

CISA ends its weekly vulnerability bulletin, a CVSS-sorted digest that never flagged exploitation

CISA will stop its weekly Vulnerability Bulletin on 28 September. Its final full issue listed 3,783 CVEs sorted by vendors' own CVSS scores, and nine of that week's 14 exploited CVEs had federal deadlines before it arrived.

By Parminder Kumar Sharma · · 17 min read

A tall stack of printed listings with a red tab and a long printout spilling off a desk beside a calendar and a laptop.

Nine federal deadlines arrived before the digest did

Between Monday 7 and Sunday 13 September 2026, CISA added 14 CVEs to its Known Exploited Vulnerabilities (KEV) catalogue. Nine of them carried a three-day federal remediation deadline that fell on or before Monday 14 September. That Monday was the day CISA released the weekly Vulnerability Bulletin covering the same week, SB26-257.

That issue listed 3,783 CVEs. Six of the 14 exploited CVEs were among them, and one of those six, a Google Chromium V8 flaw, sat under "Severity Not Yet Assigned". Seven of the other eight had appeared in earlier weekly issues, four of them also under "Not Yet Assigned". The eighth, a Cisco Firewall Management Center flaw that its CNA scored CVSS 10.0, never appeared in any weekly issue: it was published on 4 March 2026, during an eight-week stretch in which CISA issued no bulletins at all.

On 16 September CISA announced that it will discontinue the weekly Vulnerability Bulletin on 28 September 2026.

Timeline of the 14 CVEs added to CISA KEV from 7 to 13 September 2026, each with a bar to its federal due date. Nine three-day deadlines end on or before 14 September, when bulletin SB26-257 was released. Placement: five in SB26-257 as High; Chromium V8 in SB26-257 as Not Yet Assigned; N-able, two MikroTik and Citrix in earlier issues as Not Yet Assigned; Fortinet and two JFrog in earlier issues as High; Cisco Firewall Management Center in no issue.
Drawn from the CISA KEV catalogue JSON (version 2026.09.16) and the CISA weekly bulletins SB26-020 to SB26-257, all fetched on 17 September 2026.

What those numbers do not establish. They do not show that anyone missed a patch because of the bulletin, or that the bulletin was ever meant to warn about exploitation. The KEV due dates bind US federal civilian agencies, not UK organisations. And retiring the bulletin does not retire any data, because every entry in it was taken from CVE records that remain public.

What the numbers do show is narrower and more useful. The weekly bulletin was a list of CVEs published in a given week, sorted by a CVSS score. It never carried an exploitation signal. The thing being switched off was never the thing that told you what to patch first, and any triage process that treated it that way has had a gap for some time.

What CISA announced, and what it did not say

The announcement went to Vulnerability Bulletin email subscribers on 16 September. CISA says it will stop the bulletin "as part of its shift from severity-based vulnerability management to a modern, risk-based approach", and ties the change to Binding Operational Directive 26-04, issued on 10 June 2026.

It names three places where it "will continue to provide risk-focused vulnerability information": the KEV catalogue, CISA Cybersecurity Alerts and Advisories, and CVE. It tells current subscribers to update their GovDelivery or Granicus preferences by selecting the Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories topics, and encourages organisations to consult vendor and provider advisories directly.

A notice now sits at the top of the bulletins page. It dates the change to the end of CISA's 2026 financial year and says newly recorded vulnerabilities remain available on CVE.org. That archive currently lists 1,096 items, the earliest covering 21 January to 3 February 2004.

The Register reported the change the same day. It pointed out that CISA did not explain why it chose to scrap the bulletin rather than adapt it to the new directive. It also suggested the list may simply have grown too large for a weekly email. That suggestion is The Register's inference, not CISA's stated reason, although the volume figures below are consistent with it.

What CISA's announcement and bulletins page state, and what they leave out. Sources: CISA GovDelivery bulletin of 16 September 2026 and the cisa.gov bulletins page, both read on 17 September 2026.

QuestionStated by CISANot stated
When does it stop?28 September 2026, the end of CISA's 2026 financial yearWhether the issue covering the week of 14 September will still be published
Why?Alignment with BOD 26-04 and a risk-based rather than severity-based approachWhy the format was retired rather than adapted; any subscriber or usage figures
What should readers use?KEV catalogue, Cybersecurity Alerts and Advisories, CVE.org, vendor advisoriesA like-for-like weekly list of newly published CVEs
What must subscribers do?Switch GovDelivery topics to KEV Catalog and Cybersecurity AdvisoriesWhether existing subscriptions will be moved automatically
What happens to the archive?Nothing announcedWhether the 1,096 archived bulletins stay online
Who is affected?Subscribers, security teams, critical infrastructure and SLTT partners that relied on weekly CVSS-based summariesHow many subscribers there are, in the US or elsewhere

What the bulletin actually contained

Each issue opened with the same description: a summary of new vulnerabilities "recorded in the past week", organised by CVSS base score into High (7.0 to 10.0), Medium (4.0 to 6.9) and Low (0.0 to 3.9), with a fourth table for CVEs without a score. The page also carried a caveat that is easy to skim past: some of the information "is not a direct result of CISA analysis".

It is often described as a weekly summary of the NIST National Vulnerability Database (NVD). That was true of its links until spring 2025, but it has not been true since. The issue for the week of 7 April 2025 (SB25-104) linked each CVE to nvd.nist.gov. From the following issue (SB25-111, week of 14 April 2025) every CVE link points to a record on cve.org, and all 3,783 links in the final full issue do the same. The current introductory text does not mention the NVD. We could not retrieve earlier versions of that text to see whether it once named the NVD.

The scores came from the CVE records themselves. All 2,791 entries in SB26-257's High, Medium and Low tables match the CVSS v3.x base score that the CVE Numbering Authority (CNA) put in its own part of the record. In most cases a CNA is the vendor scoring its own product: that week Microsoft assigned 967 of the CVEs, Adobe 168 and Dell 115. The bulletin did not re-score anything; it sorted what the CNAs had written.

Size of the weekly bulletin, same seven calendar weeks a year apart. Source: CISA weekly bulletins SB25-216 to SB25-258 and SB26-215 to SB26-257, entries counted from the published tables.

MeasureWeeks of 28 Jul to 8 Sep 2025Weeks of 27 Jul to 7 Sep 2026
Entries across seven issues5,96419,807
Average entries per issue8522,830
Entries in the High table1,5748,130
Largest single issue1,0993,882

The final full issue, covering 7 to 13 September, listed 3,783 CVEs from 113 CNAs, 1,700 of them in the High table. For that week the NVD API returns 3,804 CVEs with a publication date in the same seven days, so the bulletin's count equals about 99.4% of that figure.

It was not always that complete. CISA's listing shows no issues for the six weeks beginning 29 September to 3 November 2025, and none for the eight weeks beginning 9 February to 30 March 2026; the next issue in each case covered only its own week. The issues for the weeks of 13 and 20 April 2026 listed 170 and 59 entries, against 1,178 and 1,469 CVEs published in those weeks according to the NVD API, which is roughly 14% and 4%. None of those pages carries a note explaining the shortfall. A team that treated the bulletin as its weekly list of everything new had no list at all for 14 weeks of the past year, and a badly incomplete one for at least two more, without being told.

Two comforting labels, and a third

"High" was a band, not a priority. In the final issue 1,700 CVEs sat in the High table. Five of them were in the KEV catalogue. A CVSS base score describes how bad a flaw could be in the abstract; it says nothing about whether anyone is exploiting it or whether you run the product.

"Not Yet Assigned" did not mean pending, and it did not mean low. It meant the CNA had not supplied a CVSS v3.x score. Of the 992 entries in that table in SB26-257, 984 had no CNA CVSS v3.x score in the record on 17 September. 271 had a CNA CVSS v4.0 score and nothing else, and for 268 of those the CNA's part of the record had not changed since before the issue was released, so the v4.0 score was already there when the bulletin filed it as unscored. 112 of those 268 scored 7.0 or more under CVSS v4.0, and 33 scored 9.0 or more. All 230 CVEs assigned by the Chrome CNA that week went into the same table.

The exploited examples are the sharpest. SB26-250, released on Tuesday 8 September, filed N-able N-central CVE-2026-86218 under "Not Yet Assigned". Its CNA had scored it CVSS v4.0 10.0 on 6 September. CISA added it to KEV the same Tuesday with a due date of 11 September. The two MikroTik RouterOS flaws added on 10 September (CNA CVSS v4.0 9.2 and 8.8) were in the same table of the same issue, and Citrix NetScaler CVE-2026-19490 (CNA CVSS v4.0 9.3) had been filed there in SB26-236 in August.

The third label is CISA's own: "risk-based". BOD 26-04 says CISA publishes KEV status, automatability and technical impact "for every CVE ID" through its Vulnrichment programme, which writes Stakeholder-Specific Vulnerability Categorization (SSVC) decision points into a CISA-ADP container in each CVE record. On 17 September, 3,281 of the 3,783 CVEs from SB26-257 (86.7%) carried that container's SSVC block. The other 502 did not, including all 443 assigned by the Linux kernel CNA that week.

Where SSVC is present, it narrows the field in the way the directive intends. 383 were marked "poc" (proof of concept), 615 as automatable and 1,426 as giving total control; 163 were both automatable and total control. Only six were marked as actively exploited, and all six were already in KEV. For exploitation, the new "risk-based" signal and the KEV are, in practice, the same list. That is not a criticism of SSVC. It does mean the risk-based view still needs two inputs no federal feed provides: whether you run the product, and whether it is exposed.

What the bulletin gave you, and where that now comes from

The weekly bulletin's contents mapped to what remains. Sources: CISA announcement of 16 September 2026, BOD 26-04, NIST NVD news of 15 April and 17 June 2026, CVEProject/cvelistV5 and cisagov/vulnrichment on GitHub, NCSC vulnerability management guidance.

What the bulletin gave youWhere that now comes fromWhat has no replacement
A Monday email listing CVEs published in the previous weekCVE.org records, the cvelistV5 GitHub repository (updated about every 7 minutes) or the NVD API filtered by publication dateA free, human-readable weekly list curated by CISA
A CVSS band for each CVEThe CNA's own score in the CVE record; CISA-ADP adds CVSS only where the CNA gave noneA routine independent second score: NIST stopped adding its own by default on 15 April 2026
Vendor, product and a short descriptionThe CVE record; the NVD has carried the record's affected-product data since 17 June 2026NVD product enrichment for CVEs outside its new priority criteria
Reference and patch linksThe CVE record's references and the vendor's own advisoryNothing: the bulletin only linked through
An exploitation signalIt never had one. The KEV catalogue, CISA-ADP SSVC data and vendor advisoriesNot a loss
A fixed weekly cadence for a triage meetingA scheduled query you run yourselfThe cadence, unless you build it
A digest a UK team could forward unchangedNCSC guidance and, for your own IP ranges and domains, NCSC Early WarningWe found no UK weekly CVE digest from the NCSC
Flow diagram: a CNA publishes the CVE record with its own CVSS score or none; CISA-ADP adds SSVC, a KEV flag and fallback CVSS; the record appears on CVE.org and cvelistV5. Four readers follow: the weekly bulletin, ending 28 September, banded by CNA CVSS v3.x only; the NVD, prioritising KEV, federal and critical software since 15 April 2026; the KEV catalogue with due dates; and the organisation, which alone knows its assets and exposure.
Drawn from the CISA announcement of 16 September 2026, BOD 26-04, the cisagov/vulnrichment README, the CVEProject/cvelistV5 repository, NIST NVD news and the CISA KEV catalogue page.

The honest summary of the table: one convenience is lost, and it was already weaker than it looked. The data is all still there, and some of it (SSVC, KEV status, affected products) is richer than anything the bulletin printed.

The NVD context matters here. On 15 April 2026 NIST said CVE submissions rose 263% between 2020 and 2025. It now prioritises enrichment for CVEs in the KEV catalogue, software used in the federal government and "critical software", and labels the rest "Lowest Priority". It also said it would no longer routinely add its own severity score where the CNA had provided one. Anyone replacing the bulletin with "just use the NVD" should expect CNA scores and a partial enrichment queue, not a second opinion on every CVE.

If you want the weekly list back, it takes two commands. The first counts and pages through every CVE the NVD records as published in a given week; the second lists KEV additions in the same window with their federal due dates.

# 1. CVEs published in a week (page with startIndex; this week had 3,804)
curl -s "https://services.nvd.nist.gov/rest/json/cves/2.0?pubStartDate=2026-09-07T00:00:00.000Z&pubEndDate=2026-09-13T23:59:59.999Z&startIndex=0" \
  | jq -r '.totalResults'

# 2. KEV additions in the same week, with due dates
curl -s https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json \
  | jq -r '.vulnerabilities[] | select(.dateAdded >= "2026-09-07" and .dateAdded <= "2026-09-13") | [.dateAdded, .dueDate, .cveID, .vendorProject, .product] | @tsv'

Method, not accusation

CISA's stated reasoning holds together. BOD 26-04 sets federal remediation timelines from four questions: is the asset publicly exposed, is the CVE in KEV, is exploitation automatable, and does it give partial or total control. A digest sorted only by CVSS base score answers none of the four. Keeping it would have sent a signal the directive is trying to retire.

The volume pressure is real too, even though CISA did not cite it. The same seven weeks of issues grew from 5,964 entries in 2025 to 19,807 in 2026, and the High table grew more than fivefold. A table of 1,700 "High" CVEs a week is not something a person can triage.

The fair criticisms are about delivery rather than direction. Subscribers got 12 days' notice (16 to 28 September). The announcement lists CVE.org as a source of "risk-focused vulnerability information", when a CVE record on its own is the same unsorted material the bulletin was built from. And the bulletin's own gaps and shortfalls over the past year went unexplained on the pages themselves.

Commercial interests deserve a plain note. CVSS scores in CVE records are frequently set by the vendor of the affected product. Two of the most active CNAs in the final week, VulnCheck (329 CVEs) and VulDB (177), are companies that sell vulnerability intelligence, and vendors in that market can be expected to pitch themselves as the bulletin's replacement. None of that makes their data wrong. It is a reason to know whose score you are reading.

The UK angle: MSPs and the Monday triage meeting

We have no figures for how many UK teams or managed service providers used the CISA bulletin, and CISA published none. Where a UK team did use it as a weekly digest, three points from UK sources matter more than the bulletin itself.

First, the NCSC's own urgent timelines already run on CISA's KEV, which is not going away. Its guidance on responding to active exploitation (version 2.1, published 1 May 2026) sets compressed update times for business-critical systems when a CVE is on the KEV. Those times are shorter than the federal ones in BOD 26-04.

NCSC compressed timelines for KEV-listed vulnerabilities in business-critical systems, compared with BOD 26-04. Sources: NCSC vulnerability management guidance, section 2 (version 2.1, 1 May 2026); BOD 26-04 Table 1.

KEV caseNCSC: install update withinBOD 26-04 federal timeline
Internet-facing, automatable, total controlImmediately, under 24 hours, plus a Cyber Incident Response investigation3 days and forensic triage
Internet-facing, not automatable, total controlUnder 48 hours, plus a Cyber Incident Response investigation3 days and forensic triage
Not internet-facing, automatable, total controlUnder 72 hours, plus a Cyber Incident Response investigation3 days and forensic triage

Second, the NCSC warns against leaning on any agency feed. Its guidance says organisations "should not solely rely on notifications from the NCSC or other cyber agencies", because agencies typically report flaws in widely deployed software. It also recommends vulnerability assessments across the whole estate at least monthly. For UK organisations, the NCSC's free Early Warning service sends alerts about malware and vulnerable services tied to the IP addresses and domain names you register through MyNCSC. It does not scan your network itself, and it is not a CVE digest.

Third, the NCSC expects the volume problem to get worse. In a blog post of 1 May 2026, NCSC chief technology officer Ollie Whitehouse told organisations to prepare for a "patch wave" as AI, in skilled hands, exposes decades of technical debt. He advised prioritising updates to the external attack surface and suggested a risk-prioritised approach such as SSVC.

For MSPs specifically, look again at the week of 7 September. Two of the 14 KEV additions were remote management products, N-able N-central and ConnectWise ScreenConnect, both with three-day federal deadlines. An MSP's own tooling is the attack path into every client, and neither the bulletin nor its retirement changes that. The NCSC guidance also says critical suppliers and managed service providers should be contractually obliged to fix exploited flaws in internet-facing systems quickly. That puts the question on the client's side of the contract as well.

What to do, in order

Take this with you

Replacing the weekly bulletin before 28 September

  • Find every person, mailbox, ticketing rule and client report that consumes the CISA Vulnerability Bulletin email or web page, including anything an MSP sends to clients.
  • Subscribe a shared team mailbox to the KEV Catalog and Cybersecurity Advisories topics in CISA's GovDelivery, and also pull the KEV JSON feed on a schedule so the process does not depend on email delivery.
  • Subscribe directly to security advisories from the vendors of your internet-facing systems and remote management tools, starting with the products on your external attack surface.
  • Replace the weekly list with a scheduled query against the NVD API or the cvelistV5 repository, filtered to the vendors and products in your asset inventory rather than read in full.
  • Stop triaging on CVSS band alone and handle CVSS v4.0-only and unscored CVEs explicitly, so they cannot fall into a no-priority bucket.
  • Add the CISA-ADP SSVC fields (exploitation, automatable, technical impact) to your triage view, and note which CVE sources, such as Linux kernel CVEs, often arrive without them.
  • Map which assets are internet-facing, because exposure is the one input no public feed can supply; UK organisations should also register their IP ranges and domains with NCSC Early Warning.
  • Adopt the NCSC compressed timelines for KEV-listed flaws in business-critical systems and agree the emergency change route with IT operations and any MSP in writing.
  • Record in the risk register what replaced the bulletin, who owns it, and a date one month out to check it caught that month's KEV additions affecting you.

The question the retirement exposes

If your Monday triage would run exactly the same way without CISA's bulletin, it was never a control, and nothing is lost on 28 September. If it would not, ask what in your process flagged N-able N-central as urgent on Tuesday 8 September. The only weekly digest that listed it that day filed it under "Not Yet Assigned", and CISA's deadline for it expired three days later.

Key facts

Sources

  1. PrimaryCISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026: the announcement email, read in full for date, reason, alternatives and subscriber instructionsCISAaccessed 2026-09-17
  2. PrimaryBulletins listing page: retirement notice, archive size and the sequence of weekly issues used to identify gapsCISAaccessed 2026-09-17
  3. PrimaryVulnerability Summary for the Week of September 7, 2026 (SB26-257): final full issue, all 3,783 entries parsedCISAaccessed 2026-09-17
  4. PrimaryVulnerability Summary for the Week of August 31, 2026 (SB26-250): placement of N-able and MikroTik CVEsCISAaccessed 2026-09-17
  5. PrimaryVulnerability Summary for the Week of April 7, 2025 (SB25-104): last issue linking CVEs to the NVDCISAaccessed 2026-09-17
  6. PrimaryVulnerability Summary for the Week of April 14, 2025 (SB25-111): first issue linking CVEs to cve.orgCISAaccessed 2026-09-17
  7. PrimaryBOD 26-04: Prioritizing Security Updates Based on Risk, including Table 1 remediation timelinesCISAaccessed 2026-09-17
  8. PrimaryKnown Exploited Vulnerabilities catalogue JSON, version 2026.09.16: additions and due datesCISAaccessed 2026-09-17
  9. PrimaryKEV catalogue page: feed formats and email subscriptionCISAaccessed 2026-09-17
  10. PrimarySubscribe to Updates from CISA: email and RSS feeds for advisoriesCISAaccessed 2026-09-17
  11. PrimaryCVE Services API record for N-able N-central CVE-2026-86218; the same API was used for all 3,783 CVEs in SB26-257CVE Programaccessed 2026-09-17
  12. PrimaryVulnrichment README: how CISA-ADP adds SSVC, KEV and fallback CVSS data to CVE recordsCISA on GitHubaccessed 2026-09-17
  13. PrimarycvelistV5 repository: official CVE List in JSON 5 format and its update frequencyCVE Program on GitHubaccessed 2026-09-17
  14. PrimaryNVD news: 15 April 2026 prioritisation change, 17 June 2026 SSVC and affected data deploymentNISTaccessed 2026-09-17
  15. PrimaryNVD CVE API query used to count CVEs published per week for comparison with bulletin countsNISTaccessed 2026-09-17
  16. PrimaryVulnerability management guidance, section 2: responding to active exploitation, including the KEV timeline tableNCSCaccessed 2026-09-17
  17. PrimaryVulnerability management guidance, section 4: monthly assessments and triageNCSCaccessed 2026-09-17
  18. PrimaryNCSC Early Warning service descriptionNCSCaccessed 2026-09-17
  19. PrimaryPreparing for a vulnerability patch wave, Ollie Whitehouse, 1 May 2026NCSCaccessed 2026-09-17
  20. Reported byCISA decides weekly vulnerability bulletin isn't necessary anymore: news pointer to the announcementThe Registeraccessed 2026-09-17

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.