The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper outlining its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program, which faced potential termination last year before receiving a last-minute reprieve. The document details a vision for a “Quality Era” aimed at improving the program, which serves as a key resource for tracking vulnerabilities in software and other products.
According to CISA, the CVE program is currently in a “Growth Era,” with over 67,000 new CVEs published in 2026 alone. The National Institute of Standards and Technology’s National Vulnerability Database has reported a staggering 263% increase in CVE submissions from 2020 to 2025, a trend accelerated by advancements in artificial intelligence. However, this surge has also intensified quality challenges within the CVE ecosystem.
“These pressures intensify quality challenges across the CVE ecosystem,” the white paper states. CISA’s plan aims to address these issues by focusing on four key areas: effective program governance, active participation from the global software community, robust data infrastructure, and reliable CVE record content. Chris Butera, CISA’s acting executive assistant director for cybersecurity, emphasized the agency’s commitment to sustaining the CVE program for the long term, informed by feedback from the CVE community.
Despite the positive outlook, some experts have expressed skepticism regarding the white paper’s effectiveness. Brian Fox, co-founder and CTO of Sonatype, noted that long-standing quality issues in CVE reports create significant challenges for security tools and developers. He stated, “I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data and in the decisions that data enables.”
Others, like Tom Alrich from the OWASP PURL Expansion Working Group, pointed out that the white paper does not adequately address the lack of machine-readable software identifiers in many new CVE records. Caitlin Condon, vice president of security research at VulnCheck, remarked that while CISA is well-positioned to set standards for quality in CVE records, the white paper serves more as a foundation for future frameworks rather than a complete solution.
For further details, the full white paper can be accessed here.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


