CISA Unveils Plan to Improve Quality of Global Vulnerability Database
The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper detailing plans to strengthen the Common Vulnerabilities and Exposures (CVE) program, the widely used system that catalogues security flaws in software and hardware. The move follows a period of uncertainty last year when the program's funding contract nearly lapsed before being extended at the last minute.
According to CISA, the CVE program has entered a 'Growth Era', with more than 67,000 new CVEs published in 2026 alone and a 263% rise in submissions to the National Vulnerability Database since 2020. The agency says artificial intelligence has accelerated this growth, but rapid expansion has also exposed inconsistencies in data quality, coordination and accountability across the ecosystem.
CISA's new plan aims to move the program into a 'Quality Era' by improving governance, encouraging wider participation from the global software community, strengthening data infrastructure and ensuring CVE records are accurate and reliable. Some vulnerability experts have questioned whether CISA, facing budget constraints, should remain the sole steward of the program, and the agency is seeking further community feedback on its proposals.