Skip to content

Security1 publisher2 min readPublished

CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.

The Watch · Security desk

Illustration accompanying CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

What happened

  • More than 67,000 CVEs had been published in 2026 as of September 18, and CVEForecast.org projects the year will close near 96,000.
  • Published September 22, the framework defines quality across four dimensions: program governance, ecosystem participation, data infrastructure and CVE record content.
  • Two of the proposed measures apply to records themselves: the share meeting defined quality criteria and how often records need correcting after publication. The paper attaches no targets or deadlines.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Anyone scoring off CVE fields still has to assume a published record may be wrong and re-check it. The framework does not say when that assumption stops being necessary.
  • exposure Uneven submissions are absorbed downstream, in the queues of the data consumers CISA lists among the parties it will keep engaging.
  • capability If CISA starts publishing the post-publication correction rate, buyers of vulnerability data get a number to compare CNAs on for the first time.
  • decision Teams sizing enrichment work for next year are budgeting against a 96,000-record year and the same in-house scrubbing they do now.

The forecast needs a faster last quarter than the year has delivered. More than 67,000 records by September 18 works out to about 257 a day across the first 261 days of 2026 [2][16]. Getting to 96,000 by December 31 takes roughly 279 a day over the remaining 104 days, about 9% above the pace so far [3][17].

The paper treats record quality as something to measure later [9]. CISA already counts volume. The NVD reported a 263% increase in CVE submissions between 2020 and 2025, and first-quarter 2026 submissions came in a third higher than the same quarter a year earlier [4][5].

CISA said automated and AI-enabled tools add pressure across the software lifecycle, from development through disclosure, while rising volume strains triage, coordinated vulnerability disclosure and CVE assignment [6]. "We are seeing a fundamental change in the economics of vulnerability research," said Russel Van Tuyl, vice president of security services at SpecterOps [10]. Van Tuyl said frontier AI is helping researchers find and validate exploit chains faster, and that CISA's framework recognized "that better vulnerability data and faster coordination must accompany faster discovery" [10][11].

Four dimensions carry the framework: program governance, ecosystem participation, data infrastructure and CVE record content. CISA said each reinforces the others while none alone delivers what it wants [7]. Measures proposed for the first three are operational: how quickly governance decisions are made, how conflicts of interest are identified and resolved, the number and diversity of active CNAs, system uptime and API performance [8]. The paper sets no targets and no deadlines [9]. Two of the measures apply to the records themselves, the share meeting defined quality criteria and how often records need correcting after publication [9].

A vulnerability manager would use that correction rate. Published, it would say how much of an initial record to act on and how much to hold for an enrichment pass. CISA presents it as a potential measure [9].

The four dimensions map onto six lines of effort from CISA's existing CVE quality strategy, covering community partnerships, government sponsorship, modernization, transparency, data quality and the CNA of Last Resort [15]. CISA called the program an "essential public good" that must remain reliable in a high-volume, AI-accelerated environment [12]. It also said technical modernization can make the program more consistent and scalable but cannot replace community engagement, governance maturation or shared expectations for vulnerability data [13]. The CNAs write the records. The framework reaches them through participation. A blog series on cve.org in the coming months will detail the infrastructure and data modernization work, and CISA said it will keep engaging CNAs, researchers, suppliers and downstream data consumers [14].

What to watch

  • Whether the cve.org blog series attaches actual figures to the two record-content measures, in particular the post-publication correction rate.</br>
  • Whether submission growth holds the one-third year-over-year pace that the first quarter of 2026 set.
  • Whether the 96,000 projection holds, given that it requires a daily publication rate above the year to date.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories