Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-25 · updated: 2026-09-25 · tags: [incident, government] · confidence: high · severity: medium · affected_sectors: [government] · au_impact: false

CISA published a white paper on 24 September proposing a quality framework for the Common Vulnerabilities and Exposures program, which it says has moved from a "Growth Era" into one where volume is degrading record reliability. The paper cites more than 67,000 new CVEs published in 2026 as of mid-September and a 263% increase in NVD submissions between 2020 and 2025, explicitly attributing part of the acceleration to AI. It names four dimensions — program governance, broad participation across the global software community, data infrastructure, and reliable record content — and commits CISA to leading the program "into the foreseeable future" after a near-miss in 2025 when the MITRE contract lapsed before a last-minute extension. The relevance to defenders is practical rather than administrative: severity scoring, KEV promotion and asset prioritisation all inherit whatever the CVE record contains, and the paper is candid that faster discovery "can expose gaps in processes, tooling, coordination, and accountability".

Attribute Detail
Sector Government
Date 2026-09-25
Source CyberScoop
Reliability Tier 2