CISA Just Switched Off the Weekly Vulnerability Bulletin — What Replaces It Only Counts Vulnerabilities That Already Have a Patch

A banner now sits at the top of CISA's Bulletins page: the weekly Vulnerability Bulletin is discontinued as of the end of FY26 — 28 September 2026 — "as part of a broader shift from severity-based vulnerability management to risk-based vulnerability prioritization." The last one published covers the week of 21 September 2026. The archive of 1,098 issues stays up; nothing new joins it.

CISA's replacement guidance is explicit about where to look instead: CVE.org for newly recorded vulnerabilities, and the KEV catalog, CISA's Alerts & Advisories, and vendor security alerts for "actionable, risk-based updates." That is not a cosmetic change to a mailing list. It is the last operational piece of BOD 26-04 falling into place, and it changes what the federal government is willing to put a clock on.

What BOD 26-04 actually did

BOD 26-04, Prioritizing Security Updates Based on Risk, was issued 10 June 2026. Buried in its text is the part most coverage skipped: it supersedes and revokes both BOD 19-02 (vulnerability remediation for internet-accessible systems, 2019) and BOD 22-01 (the 2021 directive that created the KEV catalog in the first place). The KEV catalog survives; the directive that birthed it does not.

In its place, remediation urgency for federal civilian agencies is computed from four decision points, drawn from the SSVC methodology:

  • Asset Exposure — is the vulnerable asset publicly exposed?
  • KEV Status — is the CVE ID in the KEV catalog?
  • Exploit Automation — can an adversary automate every step of exploitation?
  • Technical Impact — does exploitation yield partial or total control?

CISA supplies three of those four itself, for every CVE ID, through the Vulnrichment program. Agencies answer only Asset Exposure. That is a deliberate design: the federal government is centralising the judgement and leaving agencies the inventory question — which is, in fairness, the question only they can answer.

The severity number that the weekly bulletin was organised around does not appear in the list. CVSS is mentioned in the directive exactly once, as an analogy to explain what "technical impact" means. A CVSS 9.8 on an internal, non-automatable, partially-impacting flaw now buys you a longer timeline than a 7.5 that is in KEV and publicly exposed. That inversion is the entire point, and it is correct.

The teeth: "and forensic triage"

The sharpest clause in the directive is one phrase in Appendix A. For the worst-case cell of the timeline table, the requirement is not just to patch — the directive defines "& forensic triage" as meaning the agency must complete remediation or mitigation within three days and separately "carry out a forensic triage of the asset to assess whether the system is compromised."

This is the durable improvement. BOD 22-01 asked agencies to patch KEV entries; it did not require them to ask whether they were already breached before the patch landed. The implementation guidance (updated 25 August 2026) spells out six triage steps — scoping, evidence preservation, critical patching and stabilisation, containment, triage analysis, and an escalation decision targeted within 48–72 hours of the KEV addition — ending in a written forensic triage report that becomes an agency record.

Anyone who watched the NetScaler zero-days get a three-day deadline after being exploited before the advisory existed, or the SharePoint code-injection bug reach its federal deadline, understands why "did you check whether it already happened" needed to be written down. Patching a KEV entry on an edge appliance without hunting is how organisations discover a breach in the following quarter.

The structural gap: KEV requires that a fix already exists

Here is what deserves more attention than it is getting. CISA's own FAQ states the conditions for KEV inclusion plainly. A vulnerability enters the catalog when it:

  • has an assigned CVE ID;
  • has reliable evidence of active exploitation in the wild;
  • has clear remediation or mitigation available, such as a vendor-provided update; and
  • carries significant risk to U.S. government information systems.

Every one of those is a reasonable condition for a catalog whose purpose is to drive patching. But read them as a filter on what the new regime can see, now that the bulletin — the one CISA product that enumerated vulnerabilities without regard to whether anyone had fixed them — is gone.

A vulnerability that is unpatched by the vendor is structurally ineligible for KEV, no matter how exploitable. It receives no federal timeline, no forensic triage requirement, and now no weekly enumeration either. The signal that remains is Vulnrichment metadata on the CVE record, which is genuinely useful and genuinely not a deadline.

This is not hypothetical. Today we also covered CVE-2026-93355 in LiteLLM — an authentication bypass that hands an attacker a permanent proxy_admin account on an AI gateway holding every upstream provider key an organisation uses. It was reported to the vendor in May, disclosed publicly in September after roughly 120 days of silence, and there is no patch. Under BOD 26-04 that flaw cannot reach KEV until BerriAI ships a fix. The Kiteworks precautionary shutdown sat in the same blind spot from the opposite direction: credible enough for a vendor to take customers offline, with no CVE and no patch to hang a directive on.

The gap is not a flaw in the directive's logic — you cannot order agencies to apply a patch that does not exist. It is a gap in what the surrounding information products cover, and the bulletin's retirement widened it by one.

What the KEV catalog looks like as the load-bearing signal

We pulled the catalog directly to size what defenders are now pointed at. As of catalog version 2026.09.27, KEV holds 1,728 entries spanning 283 distinct vendors and 697 distinct products. Recent additions run at a handful per active day — three on 25 September (MikroTik RouterOS, Microsoft SharePoint, WordPress Core), two on 27 September (both Citrix NetScaler).

CISA says it aims to add qualifying vulnerabilities within 24 hours, while noting the delays that intervene: further research, insufficient evidence, unavailable mitigations, an unassigned CVE. Those caveats are honest, and they are also the shape of the coverage gap. Three of the four listed delay causes describe a vulnerability that is real and dangerous right now and simply not yet catalogable.

One FAQ answer is worth adopting regardless of whether you are a federal agency: a vulnerability that leaks login credentials is assessed as total technical impact, "because an attacker could use those credentials to obtain total control." That is the correct read, and it is one most internal severity rubrics get wrong by scoring credential disclosure as a confidentiality issue. The WSO2 JWT bypass is the reference case: a flaw that manufactures admin tokens is a total-control flaw, whatever the CVSS confidentiality metric says.

What to change in your own process this week

  • Replace the bulletin subscription before you miss it. If any part of your intake — a weekly triage meeting, a ticket-generation script, a compliance artefact — consumed CISA's bulletin, it is now consuming nothing. Point it at the KEV catalog JSON feed and CISA's Alerts & Advisories, and add vendor advisories for your actual stack.
  • Do not let KEV become your whole intake. This is the trap the retirement sets. KEV is a high-precision, deliberately low-recall feed: exploited and fixable and federally relevant. Everything unpatched, everything vendor-silent, and everything with no CVE yet is outside it by construction. Keep a second lane for those, fed by vendor advisories, GHSA, and researcher disclosures.
  • Adopt the four decision points internally. Exposure, known exploitation, exploit automation, technical impact is a better prioritisation frame than a CVSS threshold, and three of the four now arrive free on every CVE record via Vulnrichment. Private-sector teams get the federal government's triage work without the federal government's deadlines.
  • Add "did this already happen" to your KEV runbook. The forensic-triage requirement is the part worth copying verbatim. For any KEV entry on an exposed asset, patching closes the door; triage tells you whether anyone is already inside. Write down who scopes it, what evidence gets preserved first, and what the 72-hour escalation decision looks like.
  • Tag assets for exposure now. Asset Exposure is the one input nobody computes for you, and it is the input that moves timelines most. Agencies have until Phase III — 180 days from 10 June 2026 — to tag every externally reachable asset with organisation, environment, exposure, and asset type. That is a sensible schema to steal.

The honest verdict

Risk-based prioritisation beats severity-based prioritisation, and the forensic-triage mandate is a real advance over BOD 22-01. Neither claim is in doubt. The concern is narrower and worth stating precisely: the products CISA retired covered vulnerabilities indiscriminately, and the products it kept cover vulnerabilities that are already solvable. The set difference — actively dangerous, publicly known, no vendor fix — is exactly where AI infrastructure has been living all month, from unpatched gateway auth bypasses to advisories with no CVE at all. Defenders now have to staff that lane themselves.

Sources: