Security leaders and practitioners are re-evaluating traditional vulnerability management practices as the volume and complexity of threats outpace the capabilities of legacy systems. The near-shutdown of the CVE program highlighted the risks of relying solely on public vulnerability disclosures, as many real-world threats stem from misconfigurations and exposures not tracked by CVEs. Industry experts emphasize the need for a unified, risk-based approach that prioritizes exposures most likely to impact business operations, rather than attempting to address every alert or vulnerability. Continuous Threat Exposure Management (CTEM) and similar frameworks are gaining traction, focusing on validating and prioritizing the handful of exposures that truly matter to organizational resilience.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-14, the White House launched the Gold Eagle initiative to use frontier AI to identify, prioritize, and coordinate remediation of software vulnerabilities across government and critical infrastructure. The move signaled a new U.S. policy response to the scale and speed of modern vulnerability discovery and exploitation.
Infosecurity Magazine reported that ENISA was seeking top-level or root status in the CVE Program, signaling a concrete European bid for a formal governance role in vulnerability identifier management. The move went beyond general expressions of support and reflected an institutional effort to shape the program's future structure.
NIST announced it will prioritize analysis and enrichment for CVEs tied to CISA’s Known Exploited Vulnerabilities catalog, federal government software, and critical software under Executive Order 14028. Other CVEs will still be listed in the National Vulnerability Database but may no longer receive automatic enrichment, reflecting ongoing backlog and workload strain.
A senior European official said the EU wants to help support the CVE Program, signaling international backing for the vulnerability identification system amid ongoing governance and sustainability concerns. The statement marked a new policy development in the debate over how to maintain core vulnerability-tracking infrastructure.
On 2026-02-11, FIRST released its 2026 Vulnerability Forecast, projecting a median of about 59,427 new CVEs and indicating 2026 would likely be the first year to exceed 50,000 published CVEs. The report highlighted scaling challenges for defenders and the vulnerability-tracking ecosystem, with quarterly updates planned to refine the forecast.
Initial story creation
In July 2025, Alexandre Dulaunoy of CIRCL introduced GCVE.eu as a Global CVE Allocation System designed to complement the CVE Program with decentralized identifier allocation and publication. The framework proposed globally unique prefixes for GCVE Numbering Authorities, cryptographic verification, and interoperability with systems such as CVE, GHSA, and EUVD.
On 2025-04-16, CISA/DHS executed an 11-month contract extension to prevent a lapse in support for the CVE Program after concerns that the contract had not been renewed in time. The action temporarily preserved continuity for the vulnerability identification and tracking system amid uncertainty over the program's future.
On 2024-05-24, reporting indicated that the National Vulnerability Database backlog of unanalyzed vulnerabilities was increasing amid funding and resource constraints. The development highlighted mounting strain in the U.S. government's vulnerability-tracking pipeline well before NIST's later decision to narrow enrichment priorities.
LWN published a report describing a significant turning point for the CVE numbering system, indicating emerging disruption or governance changes in how vulnerability identifiers were being managed. This represents an earlier milestone in the story's evolution before GCVE.eu and later NVD policy changes.
LWN reported on efforts to introduce '!CVE' identifiers as a way to supplement the traditional CVE system, reflecting early experimentation with alternative vulnerability identification approaches. The report marked an early milestone in concerns about CVE scalability and governance that later fed into broader changes and new identifier initiatives.
29 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecsoonline.com
Open sourcescworld.com
Open sourcepraetorian.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcelwn.net
Open sourcegcve.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.