← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 16:52via CSO Online

CISA is ending its monthly vulnerability bulletin

Brief

The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA).

The agency will discontinue its weekly bulletin of known vulnerabilities from September 28 . It said that it is taking this step because of the recently introduced Binding Operational Directive (BOD 26-04) , which compels US agencies to prioritize patching vulnerabilities according to real-world risk factors.

These will include evidence of vulnerabilities being identified in the wild, as opposed to the previous criterion of severity scores. It is not clear why the agency cannot continue to issue weekly bulletins while complying with the demands of BOD.

What could be a more pressing issue for CISA is the proliferation of AI-generated threats.

Read more on CSO Online→