CISA's weekly vulnerability bulletin ends today. The largest section of the final edition has no severity at all
The last edition lists 2,882 CVEs. 1,161 of them, 40.3 per cent, are filed under Severity Not Yet Assigned, which is more than High, Medium or Low. The bulletin sorted by severity ends unable to assign one to its biggest group.
By Parminder Kumar Sharma · · 5 min read

The last edition, released on the last day
CISA published the final edition of its weekly Vulnerability Bulletin this morning: the Vulnerability Summary for the Week of 21 September 2026, document SB26-271, released 28 September. That is the date CISA set for the series to end.
The notice on CISA's bulletins page gives the reason in one sentence: the bulletin is being discontinued "as part of a broader shift from severity-based vulnerability management to risk-based vulnerability prioritization". Newly recorded vulnerabilities remain on CVE.org, and CISA points readers to the Known Exploited Vulnerabilities catalogue, its own alerts and advisories, and vendor security alerts instead.
The bulletin sorts every CVE recorded that week into High, Medium and Low by CVSS base score, High being 7.0 to 10.0, Medium 4.0 to 6.9 and Low 0.0 to 3.9. A fourth section holds anything without a score yet, each entry marked not yet calculated.
Counting the final edition entry by entry gives 2,882 unique CVEs:
- High: 947
- Medium: 697
- Low: 81
- Severity Not Yet Assigned: 1,161
The largest single section of the last severity-sorted bulletin is the one with no severity. 1,161 against High's 947, which is 40.3 per cent of everything the edition lists.
The previous edition, for the week of 14 September, listed 4,855 CVEs, of which 1,725 were unrated. That was 35.5 per cent, and High was still the larger section there, at 1,962. One week later the unrated share went up by nearly five points and overtook it.
What that does not establish. It does not mean 1,161 vulnerabilities will never be scored. "Not yet calculated" is a snapshot of the week the bulletin went out, and many of those entries will receive a score later. It does not mean anyone loses information: every CVE stays on CVE.org and in the National Vulnerability Database. It does not mean CISA is cutting a service, because the notice names four live alternatives. And two editions are not a trend line. They show what the model looked like at the point it was switched off, and no more.
Why the retirement is consistent, not a retreat
Sorting by CVSS band is severity-based prioritisation by definition. That is precisely the model CISA says it is leaving. So the bulletin is not being withdrawn because it was badly made. It is being withdrawn because it was an honest record of a method, and in its final edition the method could not produce an answer for its largest group.
The replacement CISA names works on a different question entirely. KEV lists what is known to be exploited, not what has been scored, and it holds 1,728 entries in total today, accumulated since 2021. One week of the old bulletin listed more CVEs than that.
The two final editions side by side
Counted from each bulletin page. The unrated share is the unrated count divided by the unique CVE count.
| Section | Week of 14 September | Week of 21 September |
|---|---|---|
| High, CVSS 7.0 to 10.0 | 1,962 | 947 |
| Medium, CVSS 4.0 to 6.9 | 1,006 | 697 |
| Low, CVSS 0.0 to 3.9 | 162 | 81 |
| Severity Not Yet Assigned | 1,725, or 35.5 per cent | 1,161, or 40.3 per cent |
What to do about it
Take this with you
Before the next Monday you expect it
- Find anything that ingests the bulletin: an RSS reader, a mailing list subscription, a scraper feeding a ticket queue. It stops now, and a silent feed looks exactly like a quiet week.
- Check any service level written in CVSS bands. Two fifths of the final edition arrived with no band, so the process needs an answer for a CVE that has none.
- Subscribe to the sources CISA names: KEV, CISA alerts and advisories, and the security feeds of the vendors you actually run.
- Do not replace the bulletin with KEV alone. KEV tells you what is being exploited, not what is newly recorded in your products. You still need a feed of new CVEs for your own estate, filtered by what you run rather than by score.
The question this leaves
The weekly bulletin was CISA's standing summary of what had been recorded. Its final edition is a fair picture of why that stopped working: more CVEs than anyone can read, sorted by a score that, for the biggest group in the list, had not yet been calculated.
The bulletin ends. The problem it recorded does not. So the question for your own process: when a new CVE arrives in something you run and nobody has scored it yet, who decides whether it matters, and on what?
Sources
- PrimaryCISA bulletins page, carrying the discontinuation notice for the weekly Vulnerability Bulletin, read 28 September 2026Cybersecurity and Infrastructure Security Agencyaccessed 2026-09-28
- PrimaryVulnerability Summary for the Week of September 21, 2026, SB26-271, the final edition, counted in fullCybersecurity and Infrastructure Security Agencyaccessed 2026-09-28
- PrimaryVulnerability Summary for the Week of September 14, 2026, SB26-264, the previous edition, counted in full for the trendCybersecurity and Infrastructure Security Agencyaccessed 2026-09-28


