News: 1757697369

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

All your vulns are belong to us! CISA wants to maintain gov control of CVE program

(2025/09/12)


The Cybersecurity and Infrastructure Security Agency (CISA) nearly let the Common Vulnerabilities and Exposures (CVE) program lapse earlier this year, but a new "vision" document it released this week signals that it now wants more control over the global standard for vulnerability identification.

CISA [1]published a two-page [2]summary of its vision board for CVE's future this week, talking it up like a Taylor Swift tour: 2025, according to CISA, is the year CVE leaves its "growth era" for a "quality era" that CISA appears intent on dominating. Nicholas Andersen, CISA's [3]recently appointed Executive Assistant Director for Cybersecurity, made the agency's vision for CVE's future clear in a blog post published alongside the vision document: It's a CISA joint.

"Over the past year, we've seen significant debate around the future of the program," Andersen [4]said . "But let me be absolutely clear: there is no national cyber defense without a reliable, government-led system for vulnerability identification."

[5]

That debate, we note, largely has to do with the fact that the CVE program came [6]close to a shutdown earlier this year when CISA nearly let MITRE's contract expire, before granting [7]an 11-month extension through March 2026.

[8]

[9]

The CVE board, a volunteer group that advises the CVE program for nonprofit MITRE (which has operated the program with US government funds since 1999), was largely kept in the dark about the lack of funding, [10]members told us earlier this year. That led some on the board to establish the CVE Foundation, pitched as a vehicle for diversified funding and vendor-neutral governance, independent of corporate or government control.

"The CVE Foundation vehemently believes the best path forward to preserve the critical service of the CVE Program is to transition it to a nonprofit entity with true international coordination, rigorous and transparent governance, and multiple funding sources from public, private, and nonprofit organizations," the CVE Foundation [11]said in July.

[12]

CISA doesn't appear thrilled with that prospect.

"The facts are simple: The mandate, mission, and momentum to lead this program into the future belongs to this agency," CISA's Andersen said in his blog post this week.

Suggestions to privatize the CVE Program or move to other alternative stewardship model might sound appealing, but the implications are serious

"Suggestions to privatize the CVE Program or move to other alternative stewardship model might sound appealing, but the implications are serious," Andersen continued. "Private entities, even with the best intentions, face conflicts of interest, prioritizing shareholder value over national security."

Over the past few years of the CVE program, Andersen added, CISA, MITRE and the CVE Board (under MITRE, not the CVE Foundation) had worked together to grow the initiative. "We do this not by dictating outcomes from Washington," Andersen said.

The vision document, we note, makes it pretty clear CISA may have realized it messed up and is now struggling to assert control of an internationally valuable program that it believes should be under its auspices. According to its vision document, the agency believes that those aforementioned conflicts of interest inherent in alternative stewardship models "reinforce the need for CISA to take a more active role in the long-term stewardship of the CVE Program."

[13]

We asked CISA what that direct control would look like, but the agency wouldn't answer our questions, instead directing us to the vision document and Andersen's blog post.

[14]Trump's cyber czar pick grilled over CISA cuts: 'If we have a cyber 9/11, you're the guy'

[15]Dems demand audit of CVE program as Federal funding remains uncertain

[16]CISA loses another senior exec - and the budget cuts haven't even started yet

[17]CISA slammed for role in 'censorship industrial complex' as budget faces possible $500M cut

MITRE's response wasn't particularly enlightening either, with the nonprofit only expressing wishes that things would just go back to the way they used to be.

“MITRE remains committed to CVE as a critical global resource," the organization told us in an email. "We look forward to continuing our support to CISA and CVE’s many partners to help realize this vision which will strengthen and position CVE for continued success in the years to come.”

CISA declined to answer questions about whether its funding of the CVE program had been extended beyond early 2026, or anything else about its vision for the program's future.

Given the language in the vision doc and Andersen's comments, the future of the CVE program is going to be a path laden with conflict, uncertainty, and trouble for those who rely on it. ®

Get our [18]Tech Resources



[1] https://www.cisa.gov/news-events/news/cisa-presents-vision-common-vulnerabilities-and-exposures-cve-program

[2] https://www.cisa.gov/resources-tools/resources/cisa-strategic-focus-cve-quality-cyber-secure-future

[3] https://www.cisa.gov/news-events/news/cisa-announces-nicholas-andersen-new-executive-assistant-director-cybersecurity

[4] https://www.cisa.gov/news-events/news/mandate-mission-and-momentum-lead-cve-program-future-belongs-cisa

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aMSX9l3CrlDqmPv6iWYeXAAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://www.theregister.com/2025/04/16/homeland_security_funding_for_cve/

[7] https://www.theregister.com/2025/04/16/cve_program_funding_save/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMSX9l3CrlDqmPv6iWYeXAAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aMSX9l3CrlDqmPv6iWYeXAAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2025/04/25/cve_board_funding/

[11] https://www.thecvefoundation.org/newsroom/posts/2025-07-23-ccpl-whitepaper

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMSX9l3CrlDqmPv6iWYeXAAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aMSX9l3CrlDqmPv6iWYeXAAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2025/06/05/trump_cyber_nominee_cairncross/

[15] https://www.theregister.com/2025/06/15/cybersecurity_news_in_brief/

[16] https://www.theregister.com/2025/06/12/cisa_loses_another_senior_exec/

[17] https://www.theregister.com/2025/05/06/cisa_budget_cuts/

[18] https://whitepapers.theregister.com/



More orange-stained chaos

Like a badger

They've only just realised, it seems. I'm surprised these people remember to breathe.

Unfortunately for the civilised world, the US deciding it wants to hold CVE as some national asset tells us that under this vision, even if the CVE programme continues, it can no longer be trusted. I suppose this only formalises a view on vulnerability disclosure that many of us have held for a while.

"Private entities, even with the best intentions, face conflicts of interest,"

Mentat74

Especially American ones...

Re: "Private entities, even with the best intentions, face conflicts of interest,"

Anonymous Coward

And UK ones, and German ones, and Australian ones, and French ones, basically any of them that have a CIA/NSA/DGSE equivalent. They should put it out for bids with a condition that says if you contest the outcome, you, and your management team individually, and all shareholds/debt holders, forfeit all righs to ever bid on it again.

I wouldn't worry, every AV/Security company already maintains their own internal classification system that's simply indexed to the Mitre CVE system.

A single governemnt, even with the best intentions, face conflicts of interest...

kmorwath

... and could prioritize its own interest against those of other countries.

I hope EU delivers its own database - Trumpistan may withold any information it can use against anything and anyone who the Clown-in-Chief hates today.

The American regime wants control

VoiceOfTruth

>> The vision document, we note, makes it pretty clear CISA ... is now struggling to assert control of an internationally valuable program that it believes should be under its auspices.

Yeah. American dominance. Tell America all the vulnerabilities so they can use them first. Fuck you, Nicholas Andersen. And your orange faced convicted criminal boss.

Doctor Syntax

How to make your country less trusted than it already is.

SHIFT TO THE LEFT!
SHIFT TO THE RIGHT!
POP UP, PUSH DOWN,
BYTE, BYTE, BYTE!