CISA published a white paper this week promising to fix the CVE program’s quality problem. It names four dimensions the program needs to mature: governance, ecosystem participation, data infrastructure, and record content. What it does not name is a budget, a staffing plan, or an enforcement mechanism for any of it. I do not think that omission is incidental, and I do not think the framework survives contact with the volume problem it describes.
The scale of the problem is not in dispute
CISA’s own numbers make the case for urgency better than any critic could. As of September 18, 2026, more than 67,000 new CVEs had been published this year, with the tracking site CVEForecast.org projecting 96,000 by year’s end. The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263 percent increase in CVE submissions between 2020 and 2025, with the first three months of 2026 running a third higher than the same period a year earlier. Nobody, including CISA, disputes that the CVE ecosystem is being flooded, much of it by AI-assisted vulnerability discovery tooling that finds bugs faster than the coordination infrastructure around CVE assignment was built to process.
The strongest case for CISA’s approach
Before I make the argument that this framework falls short, it deserves the strongest version of its own case. CISA’s position, reasonably stated, is that a program cannot fix a metric it has not defined. Before you can measure whether a CVE record is “complete” or “timely,” the program-wide constituency of CVE Numbering Authorities, Root organizations, and downstream tool vendors has to agree on what those words mean and who is accountable for them. A pile of new funding thrown at a program without that agreement risks building faster infrastructure for the same inconsistent output. Governance-first is not an unreasonable sequencing choice, and CISA is explicit that this white paper is meant to set the stage for more detailed technical roadmaps to follow, not replace them.
Where the sequencing argument breaks down
The problem is timing against reality. CISA’s own document says a total of 96,000 new CVEs are projected this year, a volume that will not pause while the CVE Program’s many global partners reach consensus on governance metrics. As CISA itself puts it, “while faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability.” That sentence describes a problem that is already happening, at scale, today. A governance framework whose stated next step is “a blog series on cve.org” in the coming months is not moving at the speed the problem is moving.
There is also a harder version of this critique, and it comes from CISA’s own watchdog. The Department of Homeland Security’s Office of Inspector General recently found that CISA lacks the authority to enforce compliance with its own binding cloud security directive, despite running more than 80 outreach engagements on that directive. That is the closest available precedent for how a CISA framework performs once it leaves the white paper stage and meets an ecosystem of independent organizations who are free to deprioritize it. A CVE Quality Era built on voluntary CNA participation and community working groups, with no funding line and no enforcement authority attached, is set up to encounter the exact same gap between stated policy and measured compliance.
What defenders should actually watch for
None of this means the framework is worthless. Naming CVE Record Content, the dimension that determines whether a defender’s vulnerability management tooling can actually parse and act on a given record, as one of four core pillars is a real acknowledgment of a real problem. CyberTech has covered cases where a patch existed and attackers exploited the flaw anyway, often because the underlying vulnerability data was too inconsistent for automated tooling to prioritize correctly. If the Quality Era framework produces record-content standards that vulnerability management vendors can build against, that is a genuine fix, not a paper exercise.
The test is not the white paper. It is whether the promised blog series on cve.org, due in the coming months, comes with a concrete data schema and a CNA compliance requirement, or with more governance language. Security leaders who rely on CVE data for patch prioritization should treat this framework as a signal of intent, not a fix, and continue validating vulnerability data quality through their own tooling rather than assuming CISA’s next update resolves the gap. Given the OIG’s finding on BOD 25-01, that is the safer assumption to build a program around.
Source: CISA, CVE Program: Establishing a Quality Era Framework
