The European Union Agency for Cybersecurity (ENISA) has been elevated to a "Root"-level participant in the Common Vulnerabilities and Exposures (CVE) program, granting it the authority to assign CVE identifiers and publish CVE records. This new role positions ENISA as a central coordinator for vulnerability disclosures across the European Union, aiming to reduce fragmentation, strengthen cross-border coordination, and accelerate responsible disclosure processes. ENISA will also serve as a primary contact point for vulnerabilities reported by or to the European Union Computer Security Incident Response Teams (CSIRTs).
This development is part of broader EU efforts to enhance cybersecurity, including the launch of the European Union Vulnerability Database as a counterpart to the U.S. National Vulnerability Database. ENISA is also developing a "Single Reporting Platform" for manufacturers to disclose actively exploited vulnerabilities, a requirement that will become mandatory under the Cyber Resilience Act starting in 2026. These initiatives are expected to improve the EU's ability to manage and coordinate cybersecurity vulnerabilities and bolster digital security across the union.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
ENISA was designated a CVE Program Root, giving it authority to oversee and delegate CVE Numbering Authority functions within its scope and expanding its role in the vulnerability disclosure ecosystem in Europe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
socket.dev
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.