Skip to content
Security & Trust

CISA ends weekly vulnerability bulletin and points readers to exploited flaws

The agency says it is moving from ranking flaws by severity to ranking them by risk. Your team now owns that step.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
CISA ends weekly vulnerability bulletin and points readers to exploited flaws
In brief
  • CISA has discontinued its weekly Vulnerability Bulletin as of the end of FY26, September 28, 2026, and is moving to risk-based prioritization.
  • A count of critical flaws does not show which ones attackers use. WebPulse data shows Drupal with 15 critical and 8 in the KEV Catalog, and Django with 12 critical and none.
  • Check whether your patch queue still depends on the weekly list, and whether it uses the KEV Catalog and vendor alerts.

A list of everything is not a list of what matters

For years, one way to keep up with software flaws was to read a long list each week. CISA, the US cyber agency, has retired one of those lists. Its notice says the weekly Vulnerability Bulletin was discontinued at the end of the 2026 fiscal year, on September 28, 2026.

The lesson here is simple. A list of every flaw tells you what exists. It does not tell you what to fix first. CISA frames the change as a move from ranking flaws by severity to ranking them by risk. The work of choosing what matters now sits more clearly with each organization.

What CISA announced

The agency presents the end of the bulletin as one step in a larger change of approach: less ranking by severity, more ranking by risk. Anyone who wants the full stream of newly recorded flaws can still find it on CVE.org, the public registry of flaw identifiers.

For updates worth acting on, CISA points readers to its Known Exploited Vulnerability (KEV) Catalog, its own alerts and advisories, and security notices from software vendors. The last weekly summary still listed on the page covers the week of September 21, 2026.

The notice does not say why CISA made the change beyond that shift. It also does not describe what the bulletin's readers should build to replace it. Both gaps matter to anyone who relied on the list.

Sept 28, 2026
Weekly bulletin discontinued at end of FY26
Source: CISA, Vulnerability Bulletins page (October 5, 2026)

Severity and exploitation are different measures

A "critical" label is a rating of potential impact, assigned to each flaw record (CVE). It says how much damage a flaw could do. The KEV Catalog records something else: flaws that CISA lists as exploited. Risk-based management adds the harder question of whether anyone is using the flaw.

WebPulse data shows why the two measures can diverge. The figures below come from NIST's National Vulnerability Database, matched to each framework, and are cumulative. They show how the measures differ. They do not rank how secure each framework is.

Drupal has 15 critical CVEs on record and 8 of its flaws are in the KEV Catalog. Django has 12 critical CVEs and none in KEV. Joomla has 38 critical CVEs and 2 in KEV. A count of critical flaws does not predict which ones attackers use.

15 / 8
Drupal: critical CVEs / in CISA KEV
Source: WebPulse analysis of NIST NVD and CISA KEV data (October 5, 2026)
12 / 0
Django: critical CVEs / in CISA KEV
Source: WebPulse analysis of NIST NVD and CISA KEV data (October 5, 2026)
38 / 2
Joomla: critical CVEs / in CISA KEV
Source: WebPulse analysis of NIST NVD and CISA KEV data (October 5, 2026)

Who carries the work now

A weekly summary did one job well. It put new flaws in front of people on a fixed schedule. If your team used it as a Monday reading list, that input has stopped.

The replacement sources work differently. KEV changes when exploitation is recorded, not on a calendar. Vendor alerts arrive from many vendors, each in its own format. Someone in your organization must now join these feeds to the software you actually run.

That join is the real work. It needs an accurate inventory of your systems and their versions. Without one, a catalog of exploited flaws cannot tell you whether you are exposed.

Questions to put to your security team

First, did any process, ticket queue or report depend on the weekly bulletin? If so, what feeds it now?

Second, do we match the KEV Catalog against our own software inventory automatically, or does a person check by hand?

Third, which vendor security alerts do we subscribe to, and who reads them? Fourth, when a flaw is added to KEV, how many days pass before we know whether we run the affected product?

The bulletin was a list for everyone. Risk-based prioritization only works as a list for you.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: cisa.gov.

Compare frameworks in this analysis
Drupal vs Joomla Drupal vs Django Joomla vs Django
Share this insight