European Union officials said they want to help strengthen and modernize the Common Vulnerabilities and Exposures (CVE) Program after a 2025 contracting scare involving MITRE raised concerns about the long-term resilience of a system widely used to track and identify software flaws. ENISA cybersecurity official Hans de Vries said EU member states asked the agency to examine how to reinforce the process, arguing that such a critical global mechanism should not rely on a single U.S. government contract, while U.S. policymakers are weighing legislation that could formalize the program and expand CISA oversight.
Officials and experts also warned that weak governance or political fragility could splinter vulnerability tracking into competing systems, undermining a core pillar of global cyber defense. The debate has also turned to improving the quality and machine-readability of CVE records at issuance, as AI-enabled attacks accelerate exploitation and reduce the value of delayed enrichment; CISA said a brief renewal delay in April 2025 did not interrupt operations and that MITRE remains the program operator.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-15, ENISA's Nuno Rodrigues Carvalho said the CVE funding scare showed the need for a stable vulnerability identification system and highlighted the EU's expanding role through ENISA-led services, the EU Vulnerability Database, and CRA/NIS2 frameworks. He also called for the CVE Program to move toward a more distributed, resilient governance model without a single point of failure.
On 2026-03-27, ENISA's Hans de Vries said the agency aims to become a top-level root CNA and could serve as a last-resort authority for CVE assignments. The remarks indicated a possible expansion from general EU support for CVE modernization into a more direct operational role in vulnerability coordination.
On March 27, 2026, EU officials including ENISA's Hans de Vries publicly said the European Union wants to help strengthen and modernize the CVE program, while experts also emphasized improving record quality at issuance to keep pace with AI-enabled exploitation.
By March 2026, U.S. policymakers were considering legislation to formalize the CVE program and potentially expand CISA's oversight role as part of broader governance and accountability reforms.
After the 2025 contracting scare, EU member states asked ENISA to examine ways to strengthen and modernize the CVE process so that the critical global vulnerability-tracking mechanism is less reliant on a single U.S. contract.
Following the April 2025 renewal scare, CISA said the delay did not disrupt CVE operations and confirmed that MITRE remains the program operator.
In April 2025, a brief delay in renewing MITRE's contract to operate the Common Vulnerabilities and Exposures program triggered concern about the program's long-term sustainability and dependence on a single U.S. government contract.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcethecyberexpress.com
Open sourcenextgov.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.