CISA said the Common Vulnerabilities and Exposures (CVE) Program should be placed on firmer legal footing, but warned Congress not to impose overly prescriptive rules that could limit the program’s ability to adapt. The debate follows a 2025 funding scare tied to MITRE’s contract, which exposed the risk of relying on a single U.S. federal agreement to support a vulnerability identification system used globally.
Agency officials said CVE governance must stay flexible as artificial intelligence accelerates vulnerability discovery and as the ecosystem becomes more internationally distributed. CISA pointed to proposals that would authorize CVE within the Department of Homeland Security, formalize CISA’s role, require a modernization plan with NIST, and establish a 15-member governing board, while also noting ENISA’s expanding role as both a CVE Numbering Authority and a CVE Root as evidence that the program is moving toward a more federated global model.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
ENISA advanced its role in CVE governance by becoming a CVE Root, a position that oversees groups of CVE Numbering Authorities and supports record quality and onboarding.
Within hours of MITRE's warning, CISA extended the contract supporting CVE operations. CISA later said a broad internal contracting review had caused only a brief renewal delay and that operations continued without disruption.
MITRE warned in April 2025 that government funding supporting operation of the CVE Program was about to expire, exposing fragility in the program's support structure.
ENISA joined the CVE ecosystem as a CVE Numbering Authority, gaining the ability to assign CVE identifiers within its scope.
The Common Vulnerabilities and Exposures program was created to assign standardized identifiers to publicly known software vulnerabilities.
CISA said it supports putting the CVE Program on firmer legal footing, while cautioning that overly prescriptive legislation could make the program restrictive and less able to adapt to AI-driven discovery and international federation.
CISA announced a pilot program that would allow selected AI companies to assign CVE identifiers for vulnerabilities discovered using their own models.
The House Rules Committee did not select the CVE-related amendment to the fiscal 2027 defense authorization bill for floor consideration, preventing a full House vote on the proposal.
A legislative proposal reported in June would formally authorize the CVE Program within the Department of Homeland Security, clarify CISA's role, require a modernization plan with NIST, and create a 15-member governing board.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.