A new EU-focused vulnerability database, db.gcve.eu, has gone live under the GCVE (Global Cybersecurity Vulnerability Enumeration) initiative, providing a free, publicly accessible repository intended to support vulnerability management and improve European digital sovereignty. The service aggregates and normalizes vulnerability information from numerous public sources, aiming to reduce reliance on US-centric vulnerability databases.
The platform is built around the GNA (GCVE Numbering Authority) model, which is positioned as a decentralized alternative to traditional centralized assignment of vulnerability identifiers (e.g., CVE IDs). It is designed to allow autonomous assignment and publication of vulnerability identifiers without waiting for central approval, and it reportedly integrates data from 25+ different sources to make vulnerability records structured, searchable, and easier to operationalize for security teams.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On January 23, 2026, experts cited in reporting warned that GCVE's decentralized parallel identifier ecosystem could create duplicate or inconsistent entries, increase operational burden for defenders, and complicate coordinated disclosure. They argued its long-term value would depend on whether it complements rather than undermines global vulnerability coordination.
By January 2026, coverage explained that GCVE uses a decentralized GCVE Numbering Authority model that allows participating organizations to assign and publish vulnerability identifiers without waiting for central approval. The system was presented as backward-compatible with CVE while aiming to avoid delays and single-point dependency risks in centralized assignment.
In early January 2026, the GCVE initiative launched db.gcve.eu as a free public vulnerability database intended to reduce reliance on U.S.-centric vulnerability infrastructure and support European digital sovereignty. The platform was described as aggregating and normalizing data from more than 25 sources and offering an open API for integration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcecyberscoop.com
Open sourcescworld.com
Open sourcethecyberexpress.com
Open sourcethecyberthrone.in
Open sourcecsoonline.com
Open sourceforbes.com
Open sourcecsoonline.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.