As of September 18, more than 67,000 CVEs had been published in 2026, and CVEForecast.org projects 96,000 by year-end.
CISA lays out four quality dimensions for the CVE Program
On September 22, CISA published "The CVE Program: Establishing a Quality Era Framework," saying the program is moving "from a growth period into a new era focused on reliability, responsiveness and vulnerability data quality." The paper defines quality across four explicit dimensions: program governance, ecosystem participation, data infrastructure and CVE record content. CISA emphasized that each dimension reinforces the others and that no single improvement will deliver the reliability it seeks.
AI-enabled tools and faster discovery are changing the economics
CISA warns that automated and AI-enabled tools are accelerating discovery across the software lifecycle — increasing pressure from development through disclosure and raising volumes that strain triage, coordinated vulnerability disclosure and CVE assignment. "We are seeing a fundamental change in the economics of vulnerability research," said Russel Van Tuyl, vice president of security services at SpecterOps, adding that "frontier AI is helping researchers find and validate exploit chains faster." CISA also described the CVE Program as an "essential public good" that must remain reliable in a high-volume, AI‑accelerated environment.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogProposed measures, but no targets or deadlines
The framework lists potential measures intended to track quality without setting numeric targets or deadlines. Proposed indicators include how quickly governance decisions are made, how conflicts of interest are identified and resolved, the number and diversity of active CVE Numbering Authorities (CNAs), system uptime and API performance. For individual CVE records, CISA suggested tracking the share that meet defined quality criteria and the frequency with which records require correction after publication. The paper presents these items as possible measures rather than hard commitments.
Technical modernization vs. community engagement
CISA mapped the framework onto six lines of effort from its existing CVE quality strategy: community partnerships, government sponsorship, modernization, transparency, data quality and the program's CNA of Last Resort. The agency said technical modernization can make the program more consistent and scalable but "cannot replace community engagement, governance maturation or shared expectations for vulnerability data." CISA also announced a forthcoming blog series on cve.org that will describe infrastructure and data modernization work in greater detail.
How CNAs, researchers, and downstream data consumers are affected
- CNAs: Proposed measures explicitly include the "number and diversity of active CVE Numbering Authorities (CNAs)" and the program's CNA of Last Resort. CNAs will be watched for participation levels and will face expectations tied to system uptime and API performance.
- Researchers: Faster reporting and AI-enabled discovery make vulnerability information more valuable when records are complete and actionable. The framework acknowledges that rising volumes and uneven submission quality expose gaps in processes and accountability that researchers and coordinators will need to address.
- Downstream data consumers and suppliers: CISA framed record content and data infrastructure as critical to downstream use. Metrics such as the share of records meeting defined quality criteria and the rate at which records need correction are presented as means to measure whether vulnerability data is reliable and actionable for downstream users.
CISA said it will continue engaging CNAs, researchers, suppliers and downstream data consumers as it executes the framework. The agency has characterized the shift as a move into a "quality era" rather than an expansionary growth phase — but it stopped short of committing to specific, time-bound targets. With publication volumes already high and projected to rise substantially before year-end, CISA's next steps — the blog series, continued engagement, and how the proposed measures are adopted — will determine whether the program's quality posture keeps pace with the faster discovery environment it described.
Source: Infosecurity Magazine — CISA Charts New "Quality Era" for Global CVE Program




