The CVE programme will require increased global support and “sustained investment” to keep up with AI-powered bug disclosures, the leading US government agency has said more than a year after the scheme almost shut down.
The US Cybersecurity and Infrastructure Security Agency’s (CISA) new “Quality Era Framework” warned that faster discovery could expose gaps in the CVE process, with publications set to reach almost 100,000 in 2026.
CISA said the pressures of soaring CVE submissions “intensify quality challenges across the CVE ecosystem… [and] can expose gaps in processes, tooling, coordination, and accountability – especially when the quality of submissions is uneven.”
Government funding cuts had already put the programme at risk of collapse in mid-2025 before CISA renewed its funding, and issues have only grown since then as LLMs drive record numbers of CVE disclosures.