CISA unveils 'Quality Era' framework for CVE program as 2026 disclosures near projected 96,000
CISA published a September 22 framework to shift the CVE program from rapid growth toward reliability and data quality, as 2026 disclosures approach a projected 96,000.
CISA published the white paper "The CVE Program: Establishing a Quality Era Framework" on September 22, 2026, arguing the program must move from growth toward reliability, responsiveness, and vulnerability data quality. As of September 18, more than 67,000 CVEs had been published in 2026, and CVEForecast.org projects roughly 96,000 by year-end. The National Vulnerability Database reported a 263% increase in CVE submissions from 2020 to 2025, with first-quarter 2026 submissions one-third higher year over year; Infosecurity Magazine also cites AI-accelerated discovery as straining triage, disclosure, and CVE assignment. The framework covers four areas: governance, broader participation, supporting data infrastructure, and more reliable CVE record content. Acting cybersecurity lead Chris Butera said CISA intends to keep operating the program and invited community feedback. Both outlets note the paper presents only potential measures with no targets or deadlines, and researchers welcomed the goals but said the paper does not yet fix missing machine-readable software identifiers or publish current quality metrics. The two reports agree on all overlapping figures.
- CISA published "The CVE Program: Establishing a Quality Era Framework" on September 22, 2026
- More than 67,000 CVEs were published in 2026 as of September 18
- CVEForecast.org projects approximately 96,000 CVEs by end of 2026
- NVD CVE submissions rose 263% between 2020 and 2025
- First-quarter 2026 NVD submissions were one-third higher year over year
- Framework's four focus areas: governance, broader participation, supporting data infrastructure, and more reliable CVE record content
- Framework proposes only potential measures, with no targets or deadlines
- Acting cybersecurity lead Chris Butera said CISA intends to keep operating the CVE program and invited community feedback
Coverage timelineoldest first · each row is one article
- · 3d agoCISA outlines improvement plan for CVE program
CyberScoop· 46
CISA published a white paper to improve CVE quality as disclosure volume surges.
- · 2d agoCISA Charts New "Quality Era" for Global CVE Program
Infosecurity Magazine· 52
CISA outlined a quality framework for the CVE program as 2026 disclosures approach a projected 96,000.