Under Binding Operational Directive 26 04, the alphabetical CVE digest gives way to a four factor risk model: asset exposure, Known Exploited Vulnerabilities (KEV) status, exploit automation, technical impact.
CISA's weekly vulnerability bulletin publishes its last issue on Monday, September 28. The disappearance of the alphabetical CVE digest is the most visible retirement of the CVSS-first triage era in U.S. federal cyberdefense, and the replacement machinery has been running for months.
The bulletin landed in inboxes every Wednesday with thousands of newly recorded CVEs, sorted alphabetically by product and scored by static severity. It was useful for completeness, painful for triage. The replacement, anchored in Binding Operational Directive 26-04 published in June 2026, treats evidence of exploitation as the sorting key instead of a CVSS number. BOD 26-04 supersedes the older 2019 remediation directive (BOD 19-02) and builds on the Known Exploited Vulnerabilities (KEV) Catalog approach CISA has run since 2021 under BOD 22-01.
CISA's September 16 announcement frames the change as a move from severity-based to risk-based vulnerability management. The agency is asking federal civilian agencies, critical-infrastructure operators, and SLTT (state, local, tribal, territorial) partners to update their GovDelivery subscription preferences before September 28 to receive KEV Catalog updates and CISA Cybersecurity Advisories directly.
The four-factor model underneath BOD 26-04 names the inputs explicitly. Asset Exposure asks whether the affected system is reachable and on what kind of network. KEV Status asks whether CISA has confirmed active exploitation. Exploit Automation asks whether working exploit code is circulating. Technical Impact asks what an attacker actually gains. Severity, in the CVSS sense, is no longer the first sort. SecurityWeek's coverage notes the same migration is well underway in commercial vulnerability management; CISA is now the loudest standard-bearer to formalize it.
The specific artifacts CISA points defenders to are not new. The KEV Catalog has been the federal government's authoritative list of vulnerabilities with confirmed exploitation since 2021. CISA's Cybersecurity Alerts and Advisories cover the higher-severity, in-the-wild cases that need an immediate response. CVE.org remains the canonical identifier registry. The Vulnrichment Program, run through CISA's partnership with the CVE program, publishes KEV status, exploit automation indicators, and technical impact for every CVE so a downstream tool can ingest structured risk data instead of an alphabetical digest.
For a small security operations center that built Monday-morning triage on the weekly bulletin, the operational question is what to wire up next. The migration ask is concrete: in the GovDelivery and Granicus preference centers, swap the discontinued bulletin topic for KEV Catalog notifications and Cybersecurity Advisories. Add a vendor feed that consumes Vulnrichment JSON if the team does not already have one. The Register's wire on the change framed the move more dismissively than CISA's own announcement; the agency is not reducing its vulnerability-management mission, it is repackaging the pipeline.
The remaining tension is whether risk-based triage actually shortens the patch queue or simply moves the bottleneck upstream. CVSS scored by a static formula; the four-factor model needs a defender to judge asset exposure and exploit automation for every relevant CVE. For a team already stretched thin, that is more work per item, even if the signal-to-noise on each item improves. BOD 26-04 is binding on federal civilian agencies; private-sector SOCs and critical-infrastructure owners can adopt the model or keep their own. The bulletin disappears on September 28 either way.