CISA has published a framework intended to improve the quality and reliability of data in the global Common Vulnerabilities and Exposures (CVE) programme as vulnerability discovery accelerates. The document, published on 22 September 2026, says the programme is moving from a period of growth into a “quality era” focused on reliability, responsiveness and more useful vulnerability records. More than 67,000 CVEs had been published by 18 September 2026, while CVEForecast.org projects 96,000 by the end of the year.
The National Vulnerability Database recorded a 263% increase in CVE submissions between 2020 and 2025, with submissions in the first quarter of 2026 a third higher than during the same period a year earlier.
CISA said automated and AI-enabled tools are increasing pressure on development, disclosure, triage and CVE assignment processes, making complete and actionable records more important while exposing uneven submission quality. Its framework defines quality across programme governance, ecosystem participation, data infrastructure and CVE record content.
Potential measures include the speed of governance decisions, conflict-of-interest handling, the number and diversity of active CVE Numbering Authorities (CNAs), system uptime and API performance, as well as the proportion of records meeting quality criteria and the frequency of post-publication corrections. CISA has not set targets or deadlines for these measures.
The agency said modernisation should improve consistency and scalability, but cannot replace community engagement, stronger governance or shared expectations. Further details on infrastructure and data modernisation are due in a forthcoming cve.org blog series, with continued engagement planned with CNAs, researchers, suppliers and downstream data consumers.