Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

CVE reporting needs to evolve from its ‘growth era’ into a ‘quality era’, CISA says

A rising volume of vulnerability disclosures is driving the US cyber agency to rethink how the CVE program works – but the devil really is in the details, experts say.

• Tue, 29 Sep 2026 •
CVE reporting needs to evolve from its ‘growth era’ into a ‘quality era’, CISA says

The United States Cybersecurity & Infrastructure Security Agency has released a framework laying out the next evolution in the CVE program, claiming the need to move away from the program’s growth stage to what it is calling a “Quality Era”.

“With new CVE Numbering Authorities and Roots joining the program from around the world, and automated and AI-enabled technologies introducing new pressures across the software development lifecycle, CISA recognised the need for a holistic maturation effort to transition the program from its growth period to a new Quality Era,” the agency said in a statement last week.

“This transition paves the way for the CVE Program to respond to the pressures and challenges facing the CVE ecosystem and to continue meeting the cybersecurity community’s needs through a refocused lens on reliability, responsiveness, and data quality.”

 
 

CISA published a white paper outlining its plan, CVE Program: Establishing a Quality Era Framework, which builds on four dimensions of quality:

  • Program governance that is transparent, accountable, and effective.
  • Ecosystem participation that reflects broad, active, and global community involvement.
  • Data infrastructure that is resilient and can support core CVE operations.
  • CVE record content that cyber defenders and users can trust and rely on.

One of the key drivers of CISA’s quality drive is sheer volume. More than 67,000 CVEs have been published as of September 18 2206, and we can expect 96,000 to have been reported by the end of the year.

However, according to cyber security firm Flashpoint, while CISA’s quality goals are laudable, “actionability can't live in the record alone” – exploitation and exposure signals can change after publication, and it's that data that drives when and how organisations need to respond to any given vulnerability.

"CISA is right that the CVE Program's next chapter has to be about quality, and the industry should support that work,” Farzad Bakhtiar, Senior Director at Flashpoint, said.

“But a well-formed record and an actionable one are different things. Security teams need to know whether a vulnerability has a working exploit, whether attackers are using it, whether it touches their exposed assets, and whether there's a fix. With CVE volume on pace to approach 100,000 this year, and many vulnerabilities never receiving a CVE at all, that context is what turns vulnerability data into a prioritisation decision."

Almost 80 per cent of CVE records now include metrics such as CVSS scores and CWEs, which Flashpoint calls progress, but the most important metrics exist outside the official record. The important questions include:

  • Is there a public exploit or working proof-of-concept?
  • Is it being actively exploited, or discussed or traded by threat actors?
  • Can it be exploited remotely?
  • Is a fix or mitigation available?
  • Does it affect a product and version we use on an exposed asset?

“That last question is why the missing-identifier concern raised by critics is important,” Flashpoint said.

“Without machine-readable product data, even a perfect record can't be matched to an asset inventory.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: