Tidal Cyber Blog

CISA Is Ending Its Weekly Vulnerability Bulletin. The Bigger Story Is Why?

Written by Tidal Cyber | Sep 21, 2026, 3:30:00 PM

For more than two decades, cybersecurity has operated under a familiar assumption: find vulnerabilities, score them, patch the most severe ones, and keep going.

On September 28, CISA will stop publishing its weekly Vulnerability Bulletin, a roundup that has catalogued newly disclosed vulnerabilities since 2004. But the significance isn't that another government bulletin is disappearing. It is why CISA has decided to end it.

CISA describes the move as part of its shift from severity-based vulnerability management toward a more risk-based approach. Under its recently issued Binding Operational Directive 26-04, federal agencies are being directed to prioritize remediation based on real-world risk factors, including evidence of exploitation and exposure, rather than relying on severity scores alone. (GovDelivery)

That distinction matters. The cybersecurity problem is no longer finding enough vulnerabilities. It is determining which findings actually deserve our attention.

 

We Have a Prioritization Problem, Not a Data Problem

The weekly CISA bulletin was born in a very different era of cybersecurity. Today, vulnerability discovery is happening at extraordinary scale, while AI-assisted research is accelerating the rate at which flaws can be identified. Dark Reading notes that the growing volume of vulnerability disclosures is one factor behind CISA's move toward risk-based prioritization. (Dark Reading)

But more findings do not automatically create better security. They can create the opposite: more queues, more alerts, more remediation work and more competition for finite security resources.

At Tidal Cyber, we called this problem “CVE Myopia” last year: the tendency to make CVEs the primary lens through which organizations measure and improve security. When every critical vulnerability demands attention because of its score rather than its relevance to actual adversary activity, security becomes an exercise in managing volume rather than making informed defensive decisions. (Security Boulevard)

Read “CVE Myopia: Breaking Free with Threat-Led Defense”

CISA's decision doesn't mean vulnerabilities or severity scores no longer matter. They absolutely do. It means severity without context is not enough.

 

Risk-Based Prioritization Is the Beginning, Not the Destination

CISA's approach appropriately considers factors such as known exploitation and exposure. Its Known Exploited Vulnerabilities Catalog is an important example of moving beyond theoretical severity toward evidence of what attackers are actually exploiting. (GovDelivery)

But defenders ultimately have to go further. Knowing that a vulnerability is exploitable or has been exploited somewhere does not, by itself, tell a security team what it means to their organization.

That requires answering a different set of questions:

    • Which adversaries, techniques and procedures are relevant to us?
    • How could those adversaries actually execute an attack?
    • Can our existing capabilities and detections address those procedures?
    • Where are the defensive gaps that could increase the probability of attacker success?
    • Which changes should we prioritize to improve Defensive Effectiveness?

That is the difference between simply ranking vulnerabilities and making Threat-Led Decisions.

 

Attackers Don't Execute Severity Scores

Earlier this year, Frank Duff made a related argument in Dark Reading: assets and vulnerabilities are important, but neither tells the full story because risk emerges when adversaries execute. Procedures provide the execution-level specificity needed to understand how attackers actually carry out attacks. (Dark Reading)

Read “Assets & Vulnerabilities Are Not Your Starting Point” in Dark Reading

That distinction becomes increasingly important as vulnerability volume grows. A vulnerability can have a high CVSS score and still have limited relevance to a particular organization's threat environment. Conversely, attackers may progress toward their objectives through credential abuse, misconfigurations, legitimate administrative tools and other procedures that aren't captured by a traditional CVE-centric view at all.

But as we all know, attackers don't organize their operations around our vulnerability queues. They execute procedures using many different techniques.

The defensive question, therefore, shouldn't stop at: “What should we patch first?”

It should ultimately become: “What can the adversaries that matter actually execute against us, and can our defenses interrupt that execution?”

 

From Vulnerability Prioritization to Threat-Led Defense

This is where the broader industry shift becomes important. Risk-based vulnerability management helps security teams decide which vulnerabilities deserve attention. Threat-Led Defense expands the context by connecting relevant threat intelligence, techniques and adversary procedures with the capabilities, detections and defenses intended to address them.

That changes the unit of decision-making. Instead of treating every vulnerability, threat or ATT&CK technique as equally important, organizations can identify the adversary procedures relevant to them, understand where defenses provide coverage, expose meaningful gaps, and prioritize the actions that reduce the probability of attacker success and residual risk. You can now measure defensive effectiveness.

Importantly, coverage is not the same as effectiveness. Mapping a defense to a procedure indicates intended coverage; it does not prove that the defense will perform successfully against every implementation of that procedure. That distinction is essential if the industry is serious about moving from counting security activity to measuring meaningful defensive outcomes.

 

Stop Measuring How Much Security Work You're Doing

CISA's retirement of its weekly vulnerability bulletin is a relatively small operational change. But the philosophy behind it is much bigger.

For years, security teams have been rewarded for activity: vulnerabilities discovered, vulnerabilities patched, alerts processed, tools deployed and controls mapped. Those numbers tell us what security teams are doing. They don't necessarily tell us whether adversaries are becoming less likely to succeed.

That is the shift the industry should pay attention to. The future of defensive security isn't about ignoring vulnerabilities. It is about refusing to consider them in isolation. Assets matter. Vulnerabilities matter. Threat intelligence matters. Techniques matter. But they become far more useful when connected to procedures, which are how relevant adversaries actually execute and to the defenses designed to interrupt that execution.

CISA is moving away from a weekly inventory organized largely around vulnerability severity. Security teams should consider the larger question that move raises:

Are we still prioritizing security based on what is easiest to count or on what is most important to defend?