{"slug": "ai-powered-discovery-exposes-gaps-in-cve-programme-says-cisa", "title": "AI-powered discovery exposes \"gaps\" in CVE programme, says CISA", "summary": "CISA's new \"Quality Era Framework\" warns that AI-powered bug discovery could expose gaps in the CVE programme's processes, tooling, coordination and accountability, with CVE publications set to reach almost 100,000 in 2026. The agency said the programme needs increased global support and \"sustained investment\" to keep pace with soaring submissions, more than a year after government funding cuts nearly caused the scheme to collapse in mid-2025 before CISA renewed its funding. CISA said the pressures of rising CVE submissions \"intensify quality challenges across the CVE ecosystem.", "body_md": "The CVE programme will require increased global support and “sustained investment” to keep up with AI-powered bug disclosures, the leading US government agency has said more than a year after the scheme almost shut down.\n\nThe US Cybersecurity and Infrastructure Security Agency’s (CISA) new [__“Quality Era Framework”__](https://www.cisa.gov/sites/default/files/2026-09/cve-program-establishing-a-quality-era-framework-508c.pdf?ref=thestack.technology) warned that faster discovery could expose gaps in the CVE process, with publications set to reach almost 100,000 in 2026.\n\nCISA said the pressures of soaring CVE submissions “intensify quality challenges across the CVE ecosystem… [and] can expose gaps in processes, tooling, coordination, and accountability – especially when the quality of submissions is uneven.”\n\nGovernment funding cuts had already put the programme at risk of collapse in mid-2025 before [__CISA renewed its funding__](https://www.thestack.technology/cve-board-member-launches-new-cve-foundation-after-mitre-crisis/), and issues have only grown since then as LLMs drive [__record numbers of CVE disclosures__](https://www.thestack.technology/microsoft-shatters-patch-tuesday-record-with-nearly-1-000-fixes-released/).", "url": "https://wpnews.pro/news/ai-powered-discovery-exposes-gaps-in-cve-programme-says-cisa", "canonical_source": "https://www.thestack.technology/ai-discovery-gaps-cve-program-cisa/", "published_at": "2026-09-24 14:21:28+00:00", "updated_at": "2026-09-24 14:29:41.955240+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["CISA", "CVE programme", "Quality Era Framework", "MITRE"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ai-powered-discovery-exposes-gaps-in-cve-programme-says-cisa", "markdown": "https://wpnews.pro/news/ai-powered-discovery-exposes-gaps-in-cve-programme-says-cisa.md", "text": "https://wpnews.pro/news/ai-powered-discovery-exposes-gaps-in-cve-programme-says-cisa.txt", "jsonld": "https://wpnews.pro/news/ai-powered-discovery-exposes-gaps-in-cve-programme-says-cisa.jsonld"}}