CISA, the US cyber defence agency, said its weekly Vulnerability Bulletin ends with fiscal year 2026, on September 28. Its bulletins page lists ten weekly summaries, the newest for the week of September 21, 2026. CISA described the stop as part of a move away from ranking flaws by severity and toward ranking them by risk.
A severity score rates how bad a flaw could be in theory. Risk-based ranking asks whether attackers are actually using it. Picture a critical-rated flaw nobody is known to exploit, and a lower-rated one on the KEV list. A severity queue puts the first on top. A KEV-driven queue puts the second there. CISA said new flaw records stay on CVE.org, a public list of known flaws. It told users to rely on its Known Exploited Vulnerability (KEV) Catalog, its alerts and advisories, and vendor alerts. The KEV Catalog lists flaws known to be under attack. CISA has not said how it defines risk or what, if anything, replaces the bulletin.
Teams that used the bulletin as a weekly worklist need another trigger for triage, meaning the choice of which fixes come first. Leaders can ask who owns triage, which feeds now start it, and whether patching deadlines follow severity or active attacks.