"Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities," Hans de Vries, ENISA’s chief cybersecurity and operations officer, said in a statement.
ENISA Root expands: 20 CVE numbering authorities under one umbrella
ENISA announced that the NATO Cyber Security Centre and AISLE have joined as CVE numbering authorities under the ENISA Root, bringing the total to 20 authorities operating beneath that root. According to ENISA, 12 were added directly by ENISA and eight moved over from the MITRE Root — the U.S. nonprofit that "has handled the program’s daily work for more than 20 years." The CVE program assigns a unique record to each publicly disclosed security flaw so governments, vendors and researchers have a common marker when referring to particular vulnerabilities.
NATO Cyber Security Centre can assign CVE IDs across the NATO enterprise
The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, gained the ability to assign CVE identifiers to eligible flaws across the NATO enterprise. The agency said that authority will make tracking "more consistent" and let the alliance share information with trusted partners sooner. The centre's responsibilities include guarding NATO’s networks, watching for threats and coordinating incident response.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAISLE’s narrower authorization — and its track record
AISLE, a cybersecurity company with offices in San Francisco and Prague, received an authorization limited to vulnerabilities discovered in its own products. That narrower scope lets the company publish identifiers without waiting for a third-party authority to process a request. "Foundational," was how AISLE co-founder Jaya Baloo described the step, adding that coordinated disclosure "starts with holding your own products to the same standard you expect of everyone else." Separately from the new designation, AISLE said its researchers have disclosed hundreds of vulnerabilities in widely used open-source software — including OpenSSL, Linux, Apache and OpenEMR — each coordinated through the relevant authority for that project.
Program upheaval: CISA’s role and competing alternatives
The changes arrive while the CVE process itself has been in flux. The CVE program is run by CISA and narrowly avoided a shutdown when a last-minute, 11-month contract extension averted a shutdown in April 2025. Since then, several competing databases from European nonprofits and private entities have been stood up to try to improve coordination of how vulnerabilities are tracked, disclosed and patched. The Computer Incident Response Center Luxembourg (CIRCL) launched the Global CVE Allocation System, or GCVE, earlier this year as an alternative to the CVE program.
What this means for technologists, policymakers, and NATO
- Technologists and security teams: More authorities under the ENISA Root mean new paths to obtain CVE identifiers. AISLE’s ability to issue IDs for its own products shortens disclosure timelines for those specific vendors, while NATO’s authority centralizes tracking within the alliance — both changes alter how teams will route and coordinate vulnerability reports.
- Policymakers and regulators: The near-shutdown of the CISA-run program and the emergence of alternatives such as GCVE underscore a governance question: how will multiple roots and databases interoperate to avoid fragmentation? ENISA frames its role as making the ecosystem "more globally representative, resilient, and scalable," a claim policymakers will watch as authorities proliferate.
- NATO and allied organizations: With the NATO Cyber Security Centre able to assign CVE IDs across the enterprise, the alliance can standardize internal tracking and accelerate information-sharing with trusted partners — a capability NATO leaders have said will aid incident coordination and response.
The addition of a military alliance centre and an AI-driven startup to the ENISA Root reflects two trends named in the announcement: the need to scale vulnerability identification and the accelerating role of AI in discovering flaws. Those shifts come as the CVE system itself faces competition and contract uncertainty, raising a practical question left in plain view by the facts: as numbering authorities and alternative databases multiply, how will the many roots and registries align so that a single flaw keeps only one canonical identifier?




