
(L to R) Nuno Rodrigues Carvalho, head of sector for Incident and Vulnerability Services at the European Union Agency for Cybersecurity, and Lindsey Cerkovnik, branch chief of vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency, speak with Nextgov/FCW Cybersecurity Reporter David DiMolfetta Aug. 6 ant the Black Hat cybersecurity conference. David DiMolfetta/Staff
A key cybersecurity system is getting a closer look from Congress
A proposal to formalize the vulnerability tracking program could strengthen its foundation, but officials warn against rules that could limit its ability to adapt.
LAS VEGAS — The Cybersecurity and Infrastructure Security Agency sees value in formally placing the world’s dominant software vulnerability tracking program into federal law but is cautioning Congress against imposing rules that could make it harder to adapt as artificial intelligence and international partners reshape the system.
The Common Vulnerabilities and Exposures Program, or CVE, gives publicly known security flaws standardized identifiers so that governments, software companies and researchers can easily communicate about the same issue. It was first created in 1999, and it underpins cybersecurity discussions across both private industry and the national intelligence community.
Policymaking interest in the program followed a funding scare last year that exposed the fragility of the arrangement supporting its functions. MITRE, the scientific research giant that helps operate CVE under a federal contract, warned last April that its funding from the government would imminently expire.
CISA then extended the contract within hours, a sweeping relief for the cybersecurity community that raised fresh questions about why a major global cybersecurity resource leaned so much on a sole U.S. contract. A CISA official previously said that a “broad internal contracting review caused a brief renewal delay in April 2025, but operations continued without disruption and MITRE was ultimately retained as the program operator.”
A legislative proposal reported by Nextgov/FCW in June would formally authorize CVE within the Department of Homeland Security and establish a clearer legal role for CISA, its longtime federal sponsor.
“Defining the importance of the program in legislation in general seems like a very helpful thing,” Lindsey Cerkovnik, branch chief for vulnerability response and coordination at CISA, said Thursday during a panel at the Black Hat cybersecurity conference.
But Cerkovnik, whose office helps oversee CVE, said legislation could become counterproductive if it dictates too precisely how the program must operate.
“When you overdefine how to execute the thing, it can make it very restrictive and difficult,” she said. “In some ways, we are wary of overly-restrictive guidance” that could make CVE less nimble, agile and flexible, she added.
The congressional proposal would also require CISA and the National Institute of Standards and Technology to develop a modernization plan and establish a 15-member board to set CVE policies and priorities. Permanent seats would go to CISA, NIST and top-level CVE authorities, while rotating members would represent industry, academia, researchers and foreign governments.
Reps. Delia Ramirez, D-Ill., and George Whitesides, D-Calif., submitted the proposal as an amendment to the fiscal 2027 defense authorization bill. But the House Rules Committee didn’t select it for floor consideration, preventing it from getting a vote in the full House last month.
Cerkovnik said CISA had reviewed the proposal and saw both benefits and challenges. Formal recognition could help preserve support for the program, although CISA and DHS have maintained its operations without a lapse for more than 26 years, she said.
CISA is CVE’s sole federal sponsor, while MITRE helps execute the program alongside a global network of more than 530 CVE Numbering Authorities, known as CNAs. Those organizations — which include software vendors, research groups and national cybersecurity agencies — can assign identifiers and publish information about vulnerabilities within their areas of responsibility.
The number and variety of those participants has allowed CVE to keep pace with a growing volume of software flaws. AI, however, is widely expected to accelerate vulnerability discovery further and may require the program to make changes that its current structure did not anticipate.
Cerkovnik pointed to a recently announced AI researcher CNA pilot program that would allow selected AI companies to assign CVE identifiers for vulnerabilities uncovered through research using their own models.
That program may need to bring people with AI expertise into its leadership, she said, and rules narrowly prescribing who can serve on CVE boards or how new participants are admitted could complicate that kind of response. Cerkovnik didn’t say the current congressional proposal would block the pilot, instead using it to illustrate why the program needs room to adjust as technology changes.
CVE is also becoming less centered on the United States. The European Union Agency for Cybersecurity, known as ENISA, became a CVE Numbering Authority in 2024 and a CVE Root in November 2025. Roots oversee groups of numbering authorities, helping organizations join the program and maintaining the quality of the vulnerability records they produce.
ENISA has since begun bringing European organizations under its Root, building on the agency’s stated goal of helping strengthen and modernize CVE.
Nuno Rodrigues Carvalho, ENISA’s head of sector for incident and vulnerability services, said on the panel Thursday that the agency now wants to “step up in the coming months” to also be a top-level Root, bringing it to the same level as CISA and MITRE.
He described a more federated model in which organizations in Europe, Japan and potentially other regions oversee nearby numbering authorities and provide further support to the project.
Europe already accounts for roughly one-fifth of the organizations authorized to assign CVE identifiers, Carvalho said. ENISA also operates the European Vulnerability Database, although he emphasized that it relies on CVE identifiers rather than competing with the existing system.
Cerkovnik backed growing foreign participation, arguing the past year had reinforced the need to describe CVE as “a global program and not just a U.S.-centric program.”
AI poses another challenge by potentially increasing the number of vulnerabilities companies and governments must process. Cerkovnik said she expects CVE to scale alongside that growth but is more concerned about whether organizations can determine which flaws demand immediate attention.
“Not all vulnerabilities matter. Not all vulnerabilities matter at the same level,” she said. CISA made a similar argument in a binding directive issued in June that tells federal agencies to base patching deadlines on a variety of factors.
Some lower-risk flaws could be left until a system receives a major upgrade, while the most dangerous vulnerabilities may require action within days. That kind of triage will become more important as AI produces more findings, Cerkovnik said, because neither CVE nor the organizations relying on it can treat every newly discovered flaw as equally urgent.




