The Common Vulnerabilities and Exposures (CVE) programme has been thrown a last-minute lifeline after the US Cybersecurity and Infrastructure Security Agency (CISA) said it would extend funding for the critical database following threats that it might shut down.
Security fears around the world were triggered when the MITRE Corporation, the nonprofit which maintains the CVE database, warned in a letter to board members that the organisation’s contract with the US Government to ‘develop, operate and modernise’ the CVE programme would end today (Wednesday 16th April).
The letter, signed by MITRE’s vice president Yosry Barsoum, goes on to say that if a break in service were to occur, the organisation anticipated ‘multiple impacts to CVE’, including a deterioration of vulnerability databases affecting advisories, tool vendors, incident response operations and critical infrastructure.
Through MITRE, the programme assigns CVEs a standardised, universally recognised identifier, making it easier for organisations to track vulnerabilities. By replacing fragmented naming conventions from individual vendors with a common language, this has proven to help security teams manage their cyber-defence and quickly raise awareness of potential risks across the industry.
News that the future of the vital cybersecurity database was in jeopardy sparked global concern, with security experts warning the move could vastly increase cyber-risks and expose enterprises worldwide to greater threats.
“MITRE’s CVE program is the global location used to store, assign and track CVEs and it has proved to be an invaluable resource for many years,” Kevin Robertson, CTO of Acumen Cyber, told DIGIT.
“Cutting its funding means the world could soon lose access to the database and there will no longer be a common destination to log CVEs, which will directly hit organisations, leaving them less aware of vulnerabilities, and more exposed to exploitation.
“MITRE’s program is currently the most widely used CVE database, so it will be difficult for organisations to find a suitable alternative.”
For the moment, however, security pros can breathe a little easier. Following twenty-four hours of high anxiety within the industry, CISA issued a statement confirming it would execute the option period on the MITRE contract, extending this initially for eleven months, and reassured that there would be no lapse in critical CVE services.
“The CVE Program is invaluable to the cyber community and a priority of CISA. We appreciate our partners’ and stakeholders’ patience,” said the statement.
Before the eleventh-hour rescue, however, a coalition of CVE Board members activated a plan to transition the CVE programme to a dedicated, non-profit foundation.
In a statement, the newly minted CVE Foundation said it aimed to ‘focus solely on continuing the mission of delivering high-quality vulnerability identification and maintaining the integrity and availability of CVE data for defenders worldwide.’
Recommended reading
- Less than Half of All Exploitable Vulnerabilities Get Fixed
- Commercial Codebases Leave Gaping Vulnerabilities
- High Risk Sectors Have the Most Critical Vulnerabilities
“CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself,” said Kent Landfield, an officer of the Foundation.
“Cybersecurity professionals around the globe rely on CVE identifiers and data as part of their daily work—from security tools and advisories to threat intelligence and response.
“Without CVE, defenders are at a massive disadvantage against global cyber threats.”
Following CISA’s pledge to continue funding the CVE programme in the short term, the role of the newly announced Foundation remains unclear.
However, even with the CVE programme’s future looking somewhat more secure, MITRE itself still faces challenges, as the nonprofit recently informed Virginia state officials it plans to lay off over 400 employees after the Trump administration cancelled more than $28 million (£21.1m) in federal contracts.





