CISA Launches Framework to Enhance CVE Data Quality Amid Rising Vulnerability Discoveries
On September 22, the Cybersecurity and Infrastructure Security Agency (CISA) introduced a comprehensive framework aimed at enhancing the quality of Common Vulnerabilities and Exposures (CVE) data. This initiative emerges in response to an accelerating volume of vulnerability disclosures, driven by advancements in artificial intelligence (AI) tools that expedite the discovery process. According to CISA, the current landscape necessitates a maturation of its vulnerability identification program to ensure that it remains effective and reliable.
Transitioning to a Quality Era
The newly published document, titled CVE Program: Establishing a Quality Era Framework, outlines CISA’s vision for transitioning the CVE program from a period of rapid growth to one characterized by reliability and actionable data quality. The implications of this shift are significant; as of September 18, over 67,000 CVEs have been published in 2026 alone, with projections from CVEForecast.org estimating that this number will soar to 96,000 by year’s end. Comparatively, the National Vulnerability Database (NVD) reported a staggering 263% increase in CVE submissions from 2020 to 2025, indicating the heightened pace of cybersecurity vulnerability identification. Notably, submissions in the first quarter of 2026 already surpassed the previous year’s figures by a third, showcasing an urgent need for quality assurance.
The Impact of Accelerated Discovery
CISA highlights that the integration of automated and AI-driven tools significantly pressures various stages of the software lifecycle—from development through to disclosure. These rising volumes of vulnerabilities create challenges in triage, coordinated vulnerability disclosure, and CVE assignment. The agency emphasizes that rapid reporting can render vulnerability information more valuable, provided the records are complete and actionable. However, this acceleration also reveals inconsistencies in processes and accountability, stressing the importance of high-quality submissions.
Russel Van Tuyl, vice president of security services at SpecterOps, acknowledged a fundamental transformation in the landscape of vulnerability research. He explained that the advent of cutting-edge AI technologies has enabled researchers to identify and validate exploit chains at an unprecedented pace. Van Tuyl echoed CISA’s sentiments, underscoring that improved vulnerability data and expedited coordination are crucial in tandem with this increased speed of discovery.
CISA described the CVE Program as an "essential public good" that must retain its reliability even as it navigates a rapidly evolving and AI-driven environment.
Defining Quality Across Four Dimensions
The framework delineates quality across four critical dimensions: program governance, ecosystem participation, data infrastructure, and the content of CVE records. CISA posits that each of these dimensions is interconnected; reliance on one alone will not achieve the desired outcomes.
To advance its objectives, the agency has proposed several measures, including assessing the speed at which governance decisions are executed, identifying and resolving conflicts of interest, counting the number and diversity of active CVE Numbering Authorities (CNAs), as well as monitoring system uptime and API performance. The framework also evaluates the integrity of CVE records by how many meet defined quality standards and how often errors necessitate corrections after publication. CISA has presented these measures as potential benchmarks but has intentionally refrained from setting specific targets or deadlines.
The aforementioned dimensions correspond with six lines of effort outlined in CISA’s existing CVE quality strategy, which encompasses community partnerships, government sponsorship, modernization, transparency, data quality, and the role of the program’s CNA of Last Resort. CISA asserts that while technical modernization can enhance consistency and scalability, it cannot isolate itself from the necessity of community engagement, governance evolution, or collaborative expectations regarding vulnerability data.
Continued Engagement and Future Developments
In essence, CISA emphasizes the importance of ongoing dialogue and collaboration with CNAs, researchers, suppliers, and data consumers in the cybersecurity ecosystem. A forthcoming blog series on the CVE website will provide updates on infrastructure enhancements and data modernization efforts, ensuring that stakeholders remain informed and engaged.
As CISA seeks to navigate this new era of vulnerability disclosure, the focus on quality and collaboration will be pivotal. By setting a foundation for improved CVE data quality, the agency aims to bolster the efficacy and reliability of cybersecurity measures at a time when they are more critical than ever.

