CISA cautions against rigid rules for future of cyber vulnerability program

https://cdn.nextgov.com/media/img/cd/2026/08/07/IMG_4308/open-graph.jpg

LAS VEGAS — The Cybersecurity and Infrastructure Security Agency sees value in formally placing the world’s dominant software vulnerability tracking program into federal law but is cautioning Congress against imposing rules that could make it harder to adapt as artificial intelligence and international partners reshape the system.

The Common Vulnerabilities and Exposures Program, or CVE, gives publicly known security flaws standardized identifiers so that governments, software companies and researchers can easily communicate about the same issue. It was first created in 1999, and it underpins cybersecurity discussions across both private industry and the national intelligence community.

Policymaking interest in the program followed a funding scare last year that exposed the fragility of the arrangement supporting its functions. MITRE, the scientific research giant that helps operate CVE under a federal contract, warned last April that its funding from the government would imminently expire.

CISA then extended the contract within hours, a...

Copyright of this story solely belongs to nextgov.com. To see the full text click HERE

Read more