CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
The US Cybersecurity and Infrastructure Security Agency (CISA) has published a framework calling for a new focus on quality in the Common Vulnerabilities and Exposures (CVE) Program, the global system used to catalogue software security flaws. The move comes as vulnerability disclosures accelerate: more than 67,000 CVEs had been published in 2026 as of mid-September, with forecasts predicting nearly 96,000 by year's end. The National Vulnerability Database also reported a 263% increase in CVE submissions between 2020 and 2025.
CISA says AI tools are changing the pace and economics of vulnerability research, helping both defenders and attackers find and validate flaws faster. While this speed can make vulnerability data more valuable, it also strains the systems responsible for triaging, verifying and coordinating disclosures, sometimes leading to incomplete or inconsistent records. Industry experts, including SpecterOps's Russel Van Tuyl, say the framework reflects a recognition that faster discovery must be matched by better coordination and data quality.
The new framework sets out four areas for improvement: how the CVE Program is governed, how participants engage with it, the strength of its data infrastructure, and the completeness of individual CVE records. CISA describes the CVE Program as an “essential public good” that must stay dependable even as vulnerability discovery accelerates through automation and AI.