HomeSecurityFunding for the CVE program reduces fears of a crisis

Funding for the CVE program, easing fears of a crisis

The Cybersecurity and Infrastructure Security Agency (CISA) and the MITRE Corporation renegotiated the contract supporting the 26‑year‑old Common Vulnerabilities and Exposures (CVE) program in a way that eliminates the looming expiration that caused panic in the security community in 2025. According to sources, the program appears to have moved from a discretionary funding element to a protected line in CISA’s budget, a structural change that could prevent the kind of dramatic crisis that threatened the system last year.

See also: CISA: New Apple vulnerabilities in the KEV Catalog

CVE

For about a day in 2025, the program that supports vulnerability management tools, threat intelligence platforms and worldwide update management systems seemed to be heading toward a sudden shutdown. The cybersecurity community was startled when MITRE revealed that its contract with the U.S. Department of Homeland Security for operating the program was set to expire without renewal.

CISA finally stepped in at the last minute, issuing an emergency 11-month contract extension that kept the system running but left the global security community bracing for another funding crisis in the spring. Nearly a year later, that temporary solution was replaced by what sources describe as a more durable arrangement. The CVE board was informed during its January 21, 2026, meeting that there would be “nofunding crisis in March” and that “ongoing operations and planning extend well beyond that time frame,” according to meeting minutes that were later released.

In a statement, Nick Andersen, interim director of CISA, told CSO, “Under CISA’s leadership and support, the CVE program is fully funded and has continuously evolved and modernized to support the global vulnerability ecosystem.”

In practical terms, this change appears to elevate the vulnerability cataloging program from a discretionary funding element that could be displaced by competing priorities to a core operational program.

The improved funding outlook has also prompted the CVE Foundation — which was created during last year's uncertainty to explore alternative governance models — to reassess its next steps.

See also: CISA: Hikvision and Rockwell Automation vulnerabilities in the KEV Catalog

Funding for the CVE program, easing fears of a crisis

Despite the apparent funding stability, the contract itself remains largely opaque — even to CVE board members. A source close to the CVE program described the deal as reassuring but lacking transparency. “It’s a mysterious contract with a mysterious number that has been agreed upon and passed,” the source said.

In his statement to the CSO, CISA’s Andersen said, “CISA, in partnership with the global cybersecurity community, is committed to improving data quality, modernizing infrastructure and services, improving governance processes with more diverse representation, among other lines of effort.” A CVE board member has repeatedly requested access to the MITRE-CISA contract at successive board meetings, according to people familiar with the discussions.

MITRE has rejected these requests, invoking legal protections around the agreement between the two organizations. A separate request for the contract under the Freedom of Information Act has also remained unanswered. The CVE council itself — which has expanded to 24 members over the past years — primarily functions as an advisory body, while MITRE retains final decision-making authority for the program's operations.

The near collapse of the CVE program last year triggered a wave of emergency planning across the entire cybersecurity ecosystem. The CVE Foundation began exploring governance models that would reduce dependence on a single funding source from the US government.

At the same time, the European Union for Cybersecurity has begun developing its own vulnerability identification framework, which has already been launched. An ENISA representative said that the organization remains committed to the CVE ecosystem but does not have visibility into the program's funding arrangements.

See also: VMware Aria Operations vulnerability on CISA's KEV List

Funding for the CVE program, easing fears of a crisis

Private organizations have also taken steps to protect themselves from potential disruption. Vulnerability intelligence firm VulnCheck, for example, has kept blocks of CVE identifiers to ensure continuity if the numbering system fails. Even with the funding concern resolved, these efforts are unlikely to disappear. Structural concerns about governance and long-term independence continue to drive interest in complementary or alternative systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS