CISA Unveils 'Quality Era' Framework for the CVE Program as AI-Fueled Discovery Pushes 2026 Toward 100,000 Records
CISA Unveils 'Quality Era' Framework for the CVE Program as AI-Fueled Discovery Pushes 2026 Toward 100,000 Records
CISA has published a white paper laying out its plan for improving the CVE program, describing the components of a "Quality Era" for the world's definitive vulnerability clearinghouse — a program that came within days of collapsing in mid-2025 before a last-minute contract reprieve. The document arrives as vulnerability volume overwhelms the system: over 67,000 new CVEs have been published in 2026 as of last week, with publications on track to approach 100,000 by year-end, and the National Institute of Standards and Technology's NVD has seen a 263% increase in CVE submissions between 2020 and 2025.
Artificial intelligence is accelerating both the discovery and the strain. "These pressures intensify quality challenges across the CVE ecosystem," the white paper states. "While faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability — especially when the quality of the submissions is uneven." LLM-driven bug finding is driving record disclosure numbers, exposing process gaps faster than the program can patch them.
The framework advances data quality across four dimensions: transparent and effective program governance, broad and active participation across the global software community, data infrastructure that supports CVE operational functions, and reliable CVE record content. "CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we've done for more than 25 years without fail," said Chris Butera, acting executive assistant director for cybersecurity, describing the paper as "a program-wide maturation effort" informed by community feedback and building on an earlier strategy document.
Expert reaction has been supportive but skeptical. Sonatype CTO Brian Fox: incomplete or inconsistent records "create real downstream work for the security tools, developers, and organizations trying to determine whether they're actually affected" — but "I'll believe we've entered a 'Quality Era' when we can see the improvement in the actual data and in the decisions that data enables." Tom Alrich of the OWASP PURL Expansion Working Group says the paper ignores the program's most important problem: "a huge and growing percentage of new CVE records don't contain a machine-readable software identifier." VulnCheck's Caitlin Condon called the document "more the basis for a future framework than a full-fledged framework in itself" and asked for transparency on the metrics it suggests. The pressure is visible everywhere in the ecosystem — Microsoft's September Patch Tuesday alone carried 974 fixes, its biggest bundle ever.
What Should You Do?
- Do not wait for the program to mature. Validate and enrich CVE data in your own pipeline — EPSS scores, KEV listings and vendor advisories turn uneven records into usable signals.
- Prioritize on exploitation evidence, not severity alone. A KEV entry is a high-quality signal; a bare CVSS number on a low-quality record is a guess. Rank accordingly.
- If your organization discloses vulnerabilities, align submissions with the four quality dimensions now — complete product identifiers, tested claims and clear affected versions — before gates tighten.
- Automate your triage. At nearly 100,000 records a year, no human team reads the stream; deploy AI-assisted triage on your side to compensate for uneven quality upstream.
The WAF Angle
WAF policy management runs on vulnerability data. Rules get written from CVEs, and those mappings fail when records lack precise product identifiers — the exact gap experts flagged in the white paper's reception. Bad data means missed virtual patches, stale rule-to-CVE traceability and false confidence at triage time. The Quality Era debate is really about whether machines can trust the feed that machines consume: if your WAF tuning pipeline ingests raw CVE data, build your own validation layer — exact version matching, exploitability corroboration, and rule-to-CVE traceability — because waiting for the program to fix its data quality means running 2027 on 2024-grade signal.