The weekly vulnerability roundup CISA has published since 2004 ends this month, another casualty of the agency’s move away from scoring flaws by severity alone.
CISA’s stated reasoning is that severity tables no longer reflect what defenders can act on. The bulletins listed every newly reported CVE with its score and a short description.
The pivot took shape in July, when the agency handed federal departments remediation deadlines built from exposure and exploitation factors, such as whether an asset faces the internet and whether an attack could be automated. Only agencies are bound, but CISA wants everyone else weighing their own risk the same way.
Speaking at DEF CON in August, the agency’s vulnerability response chief, Lindsey Cerkovnik, argued that most flaws do not matter, and that the ones that do carry different weight depending on the organization.
Prioritization replaces the scoreboard
In place of base scores, CISA keeps pointing at Stakeholder-Specific Vulnerability Categorization, which folds in exploitation evidence and asset exposure. Chris Butera, the agency’s acting executive assistant director for cybersecurity, said vendors are already wiring that logic into their tooling.
Advisories continue, and the Known Exploited Vulnerabilities catalog keeps growing. What disappears is the implication that a high number is a work order. Track exposure, active exploitation and business impact instead.
