CYBERSECURITYTRACKER
TRACKING7,595 stories in this site build1,630 vulnerability news stories in this site build
Permanent story citation

CISA outlines improvement plan for CVE program

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8375

As cited

Copy frozen at (site build).

government policy

CISA outlines improvement plan for CVE program

The Cybersecurity and Infrastructure Security Agency released a white paper outlining a 'Quality Era' improvement plan for the Common Vulnerabilities and Exposures (CVE) program, which has expanded dramatically with over 67,000 new CVEs published in 2026 alone. The plan addresses governance, participation, data infrastructure, and record content across the global software community. Vulnerability experts support CISA's goals but raised concerns about incomplete implementation, missing machine-readable identifiers in CVE records, and the need for transparent measurement of progress.

Why it matters: Security practitioners relying on CVE data for vulnerability assessment and prioritization need CISA's improvements to deliver consistent, actionable records; skepticism from experts suggests quality gaps will persist without enforcement of standards and public metrics.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary