# CISA Shifts Vulnerability Prioritization

CISA ended its weekly Vulnerability Bulletin at the close of FY2026 on September 28, 2026, shifting its vulnerability-management emphasis from severity-based tracking toward risk-based prioritization using resources such as the Known Exploited Vulnerabilities (KEV) Catalog and CISA advisories. Federal vulnerability-management contractors and agencies now have less reason to rely on the weekly bulletin as a central input and greater need to prioritize exploited vulnerabilities and integrate relevant data feeds into their workflows.

- Contractors supporting federal vulnerability management should evaluate whether their processes use the KEV Catalog, CISA advisories, and automated scanner feeds to prioritize vulnerabilities amid high CVE volumes.
- A commenter reports organizational alignment with BOD 26-04, indicating that risk-based prioritization is relevant to operational planning; the signal does not specify new contract opportunities or procurement requirements.
- Organizations that relied on the bulletin should account for its end in their vulnerability-intelligence workflows and adjust any related service delivery or tooling accordingly.

**Jurisdictions:** federal
**Industries:** Information Technology, Public Safety
**Topics:** Cybersecurity
**Published:** October 05, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)

### Key Quotes
> CISA will discontinue the weekly Vulnerability Bulletin at the end of FY26 (September 28, 2026) as part of a broader shift from severity-based vulnerability management to risk-based vulnerability prioritization.
> — Original poster

> Can confirm in our own org we're moving to align with BOD 26-04. There's too much wasted effort analyzing individual CVEs when there are literally thousands a month now.
> — Community commenter (username not provided)

### Sources
- [CISA recently discontinued its new weekly Vulnerability Bulletins...](https://www.reddit.com/r/cybersecurity/comments/1wygzdn/cisa_recently_discontinued_its_new_weekly) - reddit-cybersecurity