WASHINGTON — The Cybersecurity and Infrastructure Security Agency has declared a new “Quality Era” for the Common Vulnerabilities and Exposures (CVE) Program, the global system that assigns identifiers to software flaws. The agency says the program must now focus on the reliability of its records rather than their number, as this year’s count heads toward 96,000.
The four-page framework, titled “CVE Program: Establishing a Quality Era Framework,” is dated Sept. 22, and CISA announced it the next day. It arrives in the same week that CISA shuts down another long-running vulnerability product. On Sept. 28, the agency will stop publishing its weekly Vulnerability Bulletin, which has summarized newly recorded flaws for subscribers every week.
Both moves point the same way. Federal vulnerability data is shifting from covering every flaw to prioritizing the ones that matter most, and the organizations that rely on that data will need to adjust.
“CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail,” said Chris Butera, CISA’s acting executive assistant director, in the agency’s announcement.
The Volume Problem

The framework opens with numbers. As of Sept. 18, more than 67,000 new CVEs had been published in 2026, and CVEForecast.org projects 96,000 by the end of the year. The National Institute of Standards and Technology (NIST), which runs the National Vulnerability Database (NVD), reported a 263% increase in CVE submissions between 2020 and 2025. Submissions in the first three months of 2026 ran one third higher than in the same period of 2025.
CISA links part of that growth to automation. “Automated and artificial intelligence (AI) enabled technologies introduce new pressures across the software lifecycle,” the framework states, from development and testing through vulnerability discovery, reporting and response. DHS is betting on the same technology from the defensive side: its $626 million network and cybersecurity consolidation expects bidders to use agentic AI to automate low-level responses to IT issues.
The agency does not treat the growth as good news in itself. More discovery helps defenders only “when records are complete, consistent, timely, and actionable,” the document says. Otherwise, the same acceleration “can expose gaps in processes, tooling, coordination, and accountability—especially when the quality of the submissions is uneven.”
For scale, BankInfoSecurity reported that the 2026 projection alone would equal nearly a quarter of the 396,869 CVEs recorded since the program began in 1999. Individual vendors show the same pattern: Microsoft fixed a record 974 CVEs in a single release on Sept. 8, more than twice its August total.
Four Dimensions, No Targets Yet
The framework defines quality across four dimensions and names possible ways to measure each one.

- Program governance: clear stewardship and collaborative decision-making, measured by how quickly governance decisions are made, how often governance materials are published, and how many conflicts of interest are identified and resolved.
- Ecosystem participation: broad involvement from CVE Numbering Authorities (CNAs), Roots, CNAs of Last Resort, product suppliers, researchers and governments, measured partly by the number and diversity of active participants.
- Data infrastructure: the application programming interfaces (APIs), schemas, validation libraries and the cve.org site that handle ID reservation and record publication, measured by uptime, API throughput, validation error rates and how long schema updates take to deploy.
- CVE record content: records that are “complete, accurate, timely, and actionable,” measured by the share of records that meet defined quality criteria and how often records need correcting after publication.
The document maps those dimensions to six lines of effort from CISA’s September 2025 roadmap, “CISA Strategic Focus: CVE Quality for a Cyber Secure Future.” The six are community partnerships, government sponsorship, modernization, transparency and communication, data quality improvements, and improvements to the CNA of Last Resort role.
CISA calls the metrics “potential success metrics,” and the framework includes no baselines, targets or deadlines for any of them. The agency describes the effort as “a program-wide maturation effort rather than a single initiative or technology upgrade.” It says a blog series on cve.org covering technology, infrastructure and data modernization will follow “in the coming months,” along with further Quality Era publications.
Industry Wants Numbers
Early reactions from the vulnerability-management industry welcomed the framing but questioned how CISA will show progress.
“We’ve been working around long-standing quality issues in CVE reports for decades,” Brian Fox, co-founder and chief technology officer of Sonatype, told CyberScoop. “I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data.”
Caitlin Condon, vice president of security research at VulnCheck, noted that CISA could already report much of what it proposes to measure. “Many of the potential success metrics suggested in the document can be measured today, but simply aren’t shared publicly,” she told CyberScoop.
Tom Alrich, who leads the OWASP PURL Expansion Working Group, argued that the framework misses the program’s biggest problem: “that a huge and growing percentage of new CVE records don’t contain a machine-readable software identifier.” Without one, automated tools cannot reliably match a CVE to the products an organization actually runs.
Adrian Sanabria, founder of the Defenders Initiative, was blunter. “Everything is ‘We’re going to be doing what we’re already doing, but more,'” he told BankInfoSecurity.
Other reactions were more positive. Russel Van Tuyl, vice president of security services at SpecterOps, told Infosecurity Magazine the framework recognizes “that better vulnerability data and faster coordination must accompany faster discovery.”
Enrichment Is Already Being Rationed
The complaints about quality reflect a problem that is already affecting defenders. A CVE record is only the start. Before most security tools can act on it, someone has to enrich it with a severity score, a weakness classification and a machine-readable list of affected products. For years, NIST’s NVD did most of that work.
That changed on April 15. Facing the surge in submissions, NIST announced it would prioritize enrichment for three groups: CVEs in CISA’s Known Exploited Vulnerabilities (KEV) catalog, CVEs affecting software used by the federal government, and CVEs in “critical software” as defined by Executive Order 14028. NIST committed to enriching KEV entries within one business day. Every other CVE “will still be listed in the NVD but deemed as ‘lowest priority’ and will not be immediately enriched,” the agency said. Backlogged CVEs published before March 1, 2026, were moved into a “Not Scheduled” category.
Industry estimates put the prioritized groups at roughly 15 to 20% of expected CVE volume. For the rest, organizations must rely on the data the original CNA supplied, which is why the quality of the underlying CVE record now matters much more.
The Bulletin Goes Dark
CISA’s Sept. 16 notice ending the weekly Vulnerability Bulletin makes a similar trade-off. The agency said it is moving “from severity‑based vulnerability management to a modern, risk‑based approach.” The change aligns with Binding Operational Directive 26-04, which since June has required federal agencies to prioritize fixes based on exploitation and exposure rather than severity scores alone.
After Sept. 28, CISA will direct users to three sources: the KEV catalog, CISA’s Cybersecurity Alerts and Advisories, and the CVE records themselves. Current subscribers must update their GovDelivery preferences and select “Known Exploited Vulnerabilities Catalog” and “Cybersecurity Advisories” to keep receiving updates. CISA also advises organizations to “consult vendor and provider advisories directly.”
For state and local governments, small utilities and smaller companies that used the weekly bulletin as a simple catch-all list, this is a real change. The KEV catalog lists only flaws with evidence of exploitation. It is much shorter than a weekly list of everything newly recorded, and by design it will not flag a critical flaw until someone is known to be exploiting it. CISA’s Cross-Sector Cybersecurity Performance Goals, the baseline the agency recommends for smaller critical infrastructure operators, already tell them to patch known exploited vulnerabilities first. Organizations that want early warning on flaws not yet being exploited will now have to get it from vendors or commercial feeds.
A Program That Nearly Lapsed
The Quality Era push comes about 17 months after the CVE Program nearly shut down. In April 2025, MITRE, the nonprofit that operates the program under contract to CISA, warned that federal funding was about to expire. CISA exercised an 11-month extension the night before the contract lapsed. That extension ran to March 2026 and set up a second funding cliff.
That second cliff did not happen. Minutes from a Jan. 21 CVE Board meeting record that board members were told there would be “no funding cliff in March” and that “ongoing operations and planning extend well beyond that timeframe.” CSO Online reported that the program has since moved from discretionary funding to a protected line item in CISA’s budget. MITRE has not released the contract terms to board members.
“Under CISA’s leadership and sponsorship, the CVE program is fully funded and has continually evolved and modernized to support the global vulnerability ecosystem,” Nick Andersen, CISA’s acting director, said at the time.
Resources are still a concern. Katie Moussouris, chief executive of Luta Security, told BankInfoSecurity that CISA has “lost a ton of resources,” though she expressed confidence that Congress would address the budget shortfalls.
What to Watch
- Whether CISA publishes baselines. The framework’s metrics mean little without starting values and targets. The promised cve.org blog series is the first place to look for them.
- Whether CNAs face minimum data requirements. Requiring machine-readable product identifiers and affected-version data in new records would be the most direct answer to the framework’s critics, and the most demanding for CNAs.
- How the CNA of Last Resort role changes. It is the only line of effort aimed at a single role, and it covers flaws that no vendor CNA takes responsibility for.
- What replaces the bulletin in practice. Organizations that relied on the weekly list should decide before Sept. 28 whether the KEV catalog, vendor advisories or commercial feeds will fill the gap.
- Whether volume keeps climbing. If the 96,000 projection holds and AI-assisted discovery keeps accelerating, the gap between recorded flaws and enriched flaws will be the measure of whether the Quality Era is working.
CISA has named the problem and described how it plans to measure progress. Whether the Quality Era delivers will depend less on the framework than on whether the data flowing to defenders becomes measurably more complete in the months ahead.