As cited
Copy frozen at (site build).
government policy
CISA outlines improvement plan for CVE program
The Cybersecurity and Infrastructure Security Agency released a white paper outlining a 'Quality Era' improvement plan for the Common Vulnerabilities and Exposures (CVE) program, which has expanded dramatically with over 67,000 new CVEs published in 2026 alone. The plan addresses governance, participation, data infrastructure, and record content across the global software community. Vulnerability experts support CISA's goals but raised concerns about incomplete implementation, missing machine-readable identifiers in CVE records, and the need for transparent measurement of progress.
Why it matters: Security practitioners relying on CVE data for vulnerability assessment and prioritization need CISA's improvements to deliver consistent, actionable records; skepticism from experts suggests quality gaps will persist without enforcement of standards and public metrics.
- Source published
- First seen by Cybersecurity Tracker