THE US Cybersecurity and Infrastructure Security Agency (CISA) has upgraded its vulnerability reporting and coordination platform, introducing more automation, streamlined processes and built-in tools for vulnerability researchers. From 17 September 2026, CISA began using VINCE–New Technology (VINCE-NT), replacing the Vulnerability Information and Coordination Environment (VINCE), which the agency had used since 2020. VINCE was developed by Carnegie Mellon University’s CERT Coordination Center.
CISA said VINCE-NT is a modernised, CISA-managed platform intended to improve collaboration between vulnerability reporters, suppliers and CISA case managers during coordinated disclosure. Its changes include a simpler and safer reporting interface, improved triage and prioritisation, automated advisory publication workflows, tools for collaboration while protecting sensitive information, enhanced case metrics, and stronger support for multi-party coordination and advisory development. The platform is now owned, sponsored and managed by CISA’s Coordinated Vulnerability Disclosure team.
The transition also changes CISA’s terminology: “vendors/developer/maintainer” becomes “supplier”, “product” becomes “component”, and “researcher/finder” becomes “reporter”. CISA said active VINCE cases will move to VINCE-NT over the coming weeks, with case coordinators contacting stakeholders to communicate their transition dates. Inactive cases will remain available on VINCE and will not be transferred. Organisations should update their internal procedures so new vulnerability submissions to CISA use VINCE-NT.