CISA Retires Its Weekly Vulnerability Bulletin: What MSPs Do Now
CISA is retiring its weekly vulnerability bulletin on September 28, 2026, in favor of a risk-based, KEV-first model under BOD 26-04. Here's what that means for MSPs still running CVSS-only patch cycles.
The bulletin is going away on September 28
CISA is retiring its weekly vulnerability bulletin on September 28, 2026. The agency confirmed the sunset in a notice pushed through its GovDelivery channel, and the trade press picked it up fast, from SecurityWeek to The Register to Dark Reading, all running some version of the same headline: the bulletin nobody unsubscribed from is finally getting cancelled. [1][6][9]
If you have never actually read the bulletin, you are not alone. It has run for years as a rolling digest of newly published CVEs, pulled straight from the National Vulnerability Database and organized by severity score. Useful as an archive. Not useful as a prioritization tool, because it never told anyone which of those CVEs were being exploited right now. [5]
CISA's own framing makes the reasoning explicit: the agency wants to focus its remediation guidance on exploitation and exposure, not on the sheer volume of newly disclosed CVEs. That's a policy pivot, not a staffing cut, and it lines up directly with Binding Operational Directive 26-04, which CISA issued earlier this year to reset how federal agencies prioritize patching. [1][12]
Who this actually affects
Directly, it's federal civilian executive branch agencies bound by CISA directives. Indirectly, it's every MSP and MSSP whose vulnerability management program has quietly been leaning on that weekly bulletin as a triage input, and every downstream customer whose patch cadence was built around "did CISA flag it this week." If your ticketing rules or your patch scripts reference that bulletin feed, you have five days from this article's publication to find a replacement workflow before the feed goes dark.
What BOD 26-04 actually says
BOD 26-04 tells agencies to stop treating CVSS score as the primary signal for patch urgency and start prioritizing based on whether a vulnerability is being actively exploited or sits in an exposed, reachable configuration. [12][14] That's a meaningful shift from the older model, where a 9.8 CVSS score on an internal, segmented, rarely-touched system could still outrank a 6.5 sitting on an internet-facing box under active attack.
The directive leans on CISA's Known Exploited Vulnerabilities catalog as the backbone of that prioritization, with implementation guidance spelling out how agencies are expected to fold KEV status and exposure context into remediation timelines rather than defaulting to a flat CVSS cutoff. [12][16] Coverage of the directive has been blunt about what it signals for the industry at large: the patch-everything, score-everything era is ending, and prioritization is becoming a function of what's exploitable and reachable, not what's numerically scary. [18]
Worth being precise here, because compliance categories get blended constantly in vendor marketing and it causes real confusion: BOD 26-04 is a directive that applies to federal agencies. It is not a certification, it is not an audit, and retiring the weekly bulletin does not create a new compliance obligation for the private sector. What it does is validate, at the federal policy level, an approach that risk-based security programs have been arguing for for years.
What fills the gap
There is no single drop-in replacement for the weekly bulletin, and that's the point. CISA wants agencies pulling from the KEV catalog directly, watching targeted advisories as they publish, and building exposure-aware prioritization into their own tooling rather than waiting for a weekly digest to tell them what already happened. [4][12]
For an MSP or MSSP, that means three things change in practice:
First, KEV becomes your floor, not your ceiling. If it's on the KEV list, it gets prioritized regardless of CVSS. That's not new advice, but it's now the explicit federal standard rather than a best practice you had to argue for.
Second, exposure context has to enter the equation. A vulnerability on an asset with no external reachability and no valid exploitation path in your environment is a different risk than the same CVE sitting on an internet-facing system with an open port and stale credentials. CVSS alone can't tell you that. Your telemetry can.
Third, you need something watching in real time, because a weekly cadence, bulletin or not, was already too slow for the exploitation timelines we're seeing across the CVEs Vijilan writes up regularly. Waiting seven days for a digest was never a serious control. It was a compliance checkbox that happened to also be somewhat informative.
Where Vijilan already runs this model
Here's the part that should feel less like news and more like validation: Vijilan's Global SOC has never prioritized purely on CVSS score. It correlates log and telemetry signal in real time across the platforms partners already run, whether that's CrowdStrike Falcon, Microsoft Sentinel and Defender, or SentinelOne as a monitored EDR, and takes containment action on what is actually being exploited in that specific environment. That's the exploitation-and-exposure model BOD 26-04 just formalized for federal agencies. Vijilan analysts were already running it for partners.
Concretely, that means a CVE with a modest CVSS score but active exploitation attempts against a partner's exposed asset gets escalated and contained the moment the SOC sees indicators, not the moment it clears some fixed severity threshold. And a high-scoring CVE sitting on a properly segmented, non-exposed system doesn't trigger the same fire drill, because the SOC has the telemetry to know the difference. Analysts can layer this discipline on top of whatever stack a partner or their client is already running, through ThreatRespond™, Vijilan's Managed XDR service, or through ThreatHunt™ for teams that want proactive, exploitation-informed hunting rather than a reactive queue.
What partners should do before September 28
A few practical steps, none of them dramatic:
- Audit any automation, ticketing rule, or reporting template that references the weekly bulletin feed and route it to the KEV catalog instead.
- Confirm your patch prioritization logic accounts for exploitation status and exposure, not just CVSS, if it doesn't already.
- Push clients gently away from "patch by score" thinking and toward "patch by what's actually reachable and actively exploited." It's a better conversation and it's now backed by federal policy, which helps when a client pushes back.
- If your current monitoring can't tell you which vulnerabilities in your environment are being actively probed versus which are theoretical, that's the actual gap this bulletin change exposes.
Vijilan works with MSPs, MSSPs, VARs, and distributors to close that last gap without asking partners to rip out their existing stack, and we never compete with our partners for their clients. White-label delivery is available for partners who want this capability under their own brand. If you want to see how the model works for your book of business, our MSP program page walks through the partnership structure, and pricing details are available at /pricing whenever you're ready for specifics.
The weekly bulletin is retiring because a calendar-based severity digest was never going to keep pace with exploitation timelines. Real-time, exposure-aware monitoring was always the more honest answer. CISA just made it official.
Frequently asked questions
When does CISA's weekly vulnerability bulletin end?
CISA is sunsetting the weekly vulnerability bulletin on September 28, 2026, according to the agency's GovDelivery notice and confirmed by multiple outlets covering the change.
Why is CISA discontinuing the bulletin?
CISA is shifting toward a risk-based model that prioritizes vulnerabilities based on active exploitation and exposure, aligned with Binding Operational Directive 26-04, rather than publishing a broad weekly digest organized by CVSS score.
What is BOD 26-04?
BOD 26-04 is a CISA Binding Operational Directive requiring federal civilian agencies to prioritize security updates based on exploitation risk and exposure, using the Known Exploited Vulnerabilities catalog as a primary signal, instead of relying on CVSS score alone.
Does this directly affect MSPs and private-sector companies?
BOD 26-04 legally applies to federal agencies, not private companies. But the retirement of the weekly bulletin removes a feed some MSPs used informally for triage, so private-sector teams need another source, ideally one built on exploitation and exposure signal rather than static severity scores.
What should MSPs use instead of the weekly bulletin?
CISA points toward its Known Exploited Vulnerabilities catalog and targeted advisories. MSPs should pair that with real-time telemetry correlation so prioritization reflects what is actually being exploited and reachable in a given environment, not just what CISA published that week.
Threat notes, once a week
What our SOC actually saw this week: new attack patterns, the detections we shipped against them, and what it means if you run an MSP. Written by the analysts, not by marketing.
See what 24/7 looks like when the SOC actually acts.
Book a 20-minute platform walkthrough: no slide deck, just the console.
Book a walkthrough →