Vulnerabilities

CISA Releases White Paper Outlining Plan to Improve CVE Program Data Quality and Governance

September 24, 2026 08:00 · 8 min read
CISA Releases White Paper Outlining Plan to Improve CVE Program Data Quality and Governance

CISA Publishes Strategy to Strengthen CVE Program Amid Surge in Vulnerability Reports

The Cybersecurity and Infrastructure Security Agency (CISA) released a white paper on Wednesday outlining its plan to improve the Common Vulnerabilities and Exposures (CVE) program, a critical initiative that nearly lost funding last year before receiving a last-minute extension. The document introduces what CISA calls a "Quality Era" for the CVE program, which serves as the primary global repository for vulnerability data in software and digital products.

Chris Butera, acting executive assistant director for cybersecurity at CISA, emphasized the agency’s long-term commitment to the program. "CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail," Butera stated. He added that the white paper reflects feedback from the CVE community and aims to support stronger participation, governance, and overall program maturation.

Program Faces Growing Pressures from Rising CVE Volumes and AI-Driven Discovery

CISA characterizes the current phase of the CVE program as a "Growth Era," driven by unprecedented increases in vulnerability reporting. As of last week, over 67,000 new CVEs had been published in 2026. Furthermore, the National Institute of Standards and Technology’s National Vulnerability Database (NVD) reported a 263% increase in CVE submissions between 2020 and 2025, a trend exacerbated by the growing use of artificial intelligence in vulnerability discovery.

"These pressures intensify quality challenges across the CVE ecosystem," the white paper states. "While faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability — especially when the quality of the submissions is uneven."

The acceleration in reporting, while beneficial for timely threat awareness, has highlighted systemic issues in data consistency and completeness, prompting CISA to focus on structural improvements rather than just volume handling.

Four-Pillar Plan Targets Governance, Participation, Infrastructure, and Data Quality

To address these challenges, CISA’s plan centers on advancing data quality across four key dimensions:

This framework aims to ensure that the CVE program not only keeps pace with rising demand but also delivers accurate, actionable information that organizations can trust for risk assessment and remediation.

Industry Experts Respond with Cautious Optimism and Lingering Concerns

The white paper has drawn mixed reactions from vulnerability management experts. Brian Fox, co-founder and chief technology officer at Sonatype, welcomed CISA’s acknowledgment that quality must extend beyond individual records to include governance, infrastructure, and ecosystem participation.

"We’ve been working around long-standing quality issues in CVE reports for decades. Incomplete or inconsistent records create real downstream work for the security tools, developers, and organizations trying to determine whether they’re actually affected and what to do next," Fox said. "So it’s good to see CISA acknowledge that quality has to extend beyond the record itself to governance, infrastructure, and participation across the ecosystem."

But, he added, "I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data and in the decisions that data enables."

Tom Alrich, leader of the OWASP PURL Expansion Working Group, praised the general direction of the paper but criticized its omission of a critical technical gap: the lack of machine-readable software identifiers in many CVE records.

"I support everything mentioned. I also support the flag, motherhood and apple pie," Alrich said. "However, nothing in there is going to affect the CVE program’s most important problem: that a huge and growing percentage of new CVE records don’t contain a machine-readable software identifier."

Caitlin Condon, vice president of security research at VulnCheck, agreed that CISA is well-positioned to lead on quality standards but viewed the white paper as a foundational step rather than a complete framework.

"Many of the potential success metrics suggested in the document can be measured today, but simply aren’t shared publicly," Condon said. "In future iterations on the framework, I’d hope to see more transparency on CVE metrics as they stand today, along with reasoning on why those metrics are the right ones (versus simply the things that are easiest to measure qualitatively or quantitatively)."

Condon noted that while the white paper sets the stage for improvement, meaningful progress will depend on measurable outcomes and greater openness about current performance benchmarks.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free