CISA outlines improvement plan for CVE program
CISA outlines plan to improve the CVE program's data quality and governance.
Summary
CISA has published a white paper detailing its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program, aiming to usher in a 'Quality Era' amidst a surge in reported vulnerabilities. The plan focuses on improving data quality through better governance, broader community participation, robust data infrastructure, and reliable CVE record content. Experts acknowledge the need for these improvements but express skepticism regarding the program's ability to address long-standing issues like machine-readable software identifiers.
Full text
The Cybersecurity and Infrastructure Security Agency published a paper Wednesday that lays out its plan for improving the Common Vulnerabilities and Exposures (CVE) program, a contract for which nearly ended last year before a last-minute reprieve. The white paper outlines the components of a “Quality Era” for the program, widely used as the definitive clearinghouse for data on vulnerabilities in software and other products, even as the number of CVEs surges. “CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail,” said Chris Butera, acting executive assistant director for cybersecurity. “Informed by CVE community feedback, this whitepaper communicates CISA’s effort to support and enable stronger participation and governance, a program-wide maturation effort.” The CVE program has been in a “Growth Era,” according to CISA. Over 67,000 new CVEs have been published in 2026 as of last week, and the National Institute of Standards and Technology National Vulnerability Database program has seen a 263% increase in CVE submissions between 2020 and 2025. Artificial intelligence has furthered the rise. “These pressures intensify quality challenges across the CVE ecosystem,” the white paper states. “While faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability — especially when the quality of the submissions is uneven.” The plan calls for advancing data quality across four key dimensions: transparent and effective program governance, broad and active participation across the global software community, data infrastructure that supports CVE operational functions and reliable CVE record content. Some vulnerability experts have questioned whether other organizations should take over CISA’s stewardship, given budget cuts at the agency. Butera invited further feedback from the CVE community on the white paper, which stems from an earlier strategy document on the future of the program. Some CVE experts that CyberScoop spoke to were supportive of what CISA wants to achieve, but skeptical about elements of the white paper. “We’ve been working around long-standing quality issues in CVE reports for decades. Incomplete or inconsistent records create real downstream work for the security tools, developers, and organizations trying to determine whether they’re actually affected and what to do next,” said Sonatype’s co-founder and chief technology officer Brian Fox. “So it’s good to see CISA acknowledge that quality has to extend beyond the record itself to governance, infrastructure, and participation across the ecosystem.” But, he added, “I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data and in the decisions that data enables.” Tom Alrich, who leads the OWASP PURL Expansion Working Group that’s focused on establishing a protocol for creating Product URLs for commercial software, said CISA’s white paper ignores a particularly important and growing issue. “I support everything mentioned. I also support the flag, motherhood and apple pie,” he said. “However, nothing in there is going to affect the CVE program’s most important problem: that a huge and growing percentage of new CVE records don’t contain a machine-readable software identifier.” Caitlin Condon, VulnCheck’s vice president of security research, said that “CISA and the CVE program are well-positioned to both observe challenges in this space and to create (and enforce) standards that explicitly state what ‘quality’ means in CVE records.” But she said the white paper was more the basis for a future framework than a full-fledged framework in itself. “Many of the potential success metrics suggested in the document can be measured today, but simply aren’t shared publicly,” Condon said. “In future iterations on the framework, I’d hope to see more transparency on CVE metrics as they stand today, along with reasoning on why those metrics are the right ones (versus simply the things that are easiest to measure qualitatively or quantitatively).” Share Facebook LinkedIn Twitter Copy Link Add to Preferred Sources