Security News

CISA Rolls Out Upgraded Vulnerability Reporting Platform: VINCE-NT

Infosecurity Magazine · 18 Sept 2026
Key Takeaway Australian businesses that report vulnerabilities to CISA or work with US suppliers should update their internal processes now to submit through VINCE-NT rather than the legacy platform.

The US Cybersecurity and Infrastructure Security Agency (CISA) has launched an upgraded version of its vulnerability reporting and coordination platform, moving from the Carnegie Mellon University-developed VINCE system to a new CISA-managed platform called VINCE-NT. The change, effective from September 17, 2026, brings more automation, built-in tools for researchers, and better integration with CISA's internal processes.

As part of the transition, CISA has also updated some of its terminology. What was previously called a 'vendor/developer/maintainer' is now a 'supplier,' 'product' becomes 'component,' and 'researcher/finder' is now referred to as a 'reporter.' Ownership and management of the platform has shifted to CISA's Coordinated Vulnerability Disclosure (CVD) team.

Organisations with active cases on the old VINCE platform will be contacted by a case coordinator about their transition date, while inactive cases will remain on the legacy system rather than being migrated. CISA has advised all organisations to update their internal reporting procedures so future vulnerability submissions are made through VINCE-NT rather than the old platform.

CISA vulnerability disclosure cybersecurity governance

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.