Yesterday, CISA, the US Cybersecurity & Infrastructure Security Agency, stepped in at the last minute to provide funding to allow the MITRE CVE program to remain operational.
In a statement published on the CISA website the agency said:
The CVE Program is invaluable to the cyber community and a priority for CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholder’s patience.
The action came after widespread concerns across the cyber security profession about the issue.
Resilience Forward’s initial article about this is below:
Cyber security industry sounds the alarm about expiring funding for the MITRE CVE program
The MITRE CVE program has been an important foundation in cybersecurity, logging newly discovered vulnerabilities and enabling rapid alerting. However, a letter sent on April 15th to CVE Board Members from Yosry Barsoum, VP and Director of the Centre for Securing the Homeland at MITRE, has warned that US Government funding for MITRE’s CVE program activities will cease on April 16th, putting the whole operation at risk.
The letter states that the cyber resilience impacts would be severe:
“If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of critical infrastructure,” states Yosry Barsoum.
The issue has resulted in a plethora of warnings about the consequences of loss of the CVE program from cyber security professionals around the world.
Tim Grieveson, Chief Security Officer (CSO) and EVP Information Security at ThingsRecon, told Resilience Forward:
“This is a big threat to the industry. With 25 years of consistent public funding, the CVE framework is embedded into security programmes, vendor feeds, and risk assessment workflows. Without it, we risk breaking the common language that keeps security teams aligned to identify and address vulnerabilities effectively.
“Delays in sharing vulnerability data would increase response times and give threat actors the upper hand. With regulations like SEC, NIS2, and DORA demanding real-time risk visibility, a lack of understanding of risk exposure and any delayed response could seriously hinder the ability to react effectively.
“To stay resilient, organizations must focus on maintaining a strong security posture with a clear understanding of their attack surface and that of their suppliers. Continued collaboration and information sharing within the community will be essential, especially in the absence of a central vulnerability database. This may be a unique opportunity for the industry to come together and explore private investment as a path forward, with large technology companies stepping up and collectively funding what has been lost.”
Immediate actions
Tim explains that cyber security teams can take the following precautions:
“Security teams should map internal tooling dependencies on CVE feeds and APIs to know what breaks if the database goes dark. They should identify alternative sources to maintain up-to-date vulnerability intelligence and focus on context, business impact, and proximity to ensure comprehensive coverage of current, emerging, and historic threats — i.e. basic cyber hygiene. Finally, accelerate cross-industry intelligence sharing to proactively leverage tactics, tools, and threat actor data.”






