CISA Charts New "Quality Era" for Global CVE Program
CISA outlined a quality framework for the CVE program as 2026 disclosures approach a projected 96,000.
CISA published The CVE Program: Establishing a Quality Era Framework on September 22, arguing the program must shift from growth toward reliability, responsiveness, and vulnerability data quality. As of September 18, more than 67,000 CVEs had been published in 2026, and CVEForecast.org projects about 96,000 by year-end. The National Vulnerability Database reported a 263% increase in CVE submissions from 2020 to 2025, with first-quarter 2026 submissions one-third higher year over year. The framework defines four quality dimensions but presents only potential measures, with no targets or deadlines.