The CVE Program is entering a new era focused on data reliability and record quality as disclosure volumes surge and artificial intelligence accelerates vulnerability discovery, according to a framework published by CISA on September 22. The agency's "CVE Program: Establishing a Quality Era Framework" document argues that the global vulnerability identification system must mature beyond its growth phase to keep pace with automated tools and rising submission rates. CISA called the program an essential public resource that needs to stay dependable in a high-volume, AI-driven environment.
The numbers show why urgency is mounting. By September 18, more than 67,000 CVEs had been published in 2026, and CVEForecast.org projects 96,000 by year's end, according to the framework. The National Vulnerability Database logged a 263% jump in CVE submissions between 2020 and 2025, and first-quarter 2026 submissions ran a third higher than the same period a year earlier. The acceleration exposes gaps in processes and accountability, especially when submission quality varies, CISA noted.
The agency said automated and AI-powered tools are creating pressure across the entire software lifecycle, from development through disclosure, while climbing volumes strain triage, coordinated vulnerability disclosure, and CVE assignment. Faster reporting makes vulnerability information more valuable when records are complete and actionable, CISA observed, but the same speed reveals weak points when data quality is inconsistent. "We are seeing a fundamental change in the economics of vulnerability research," said Russel Van Tuyl, vice president of security services at SpecterOps, adding that frontier AI is helping researchers find and validate exploit chains faster.
The framework defines quality across four dimensions—program governance, ecosystem participation, data infrastructure, and CVE record content—each reinforcing the others. Proposed measures include how quickly governance decisions are made and conflicts of interest resolved, the number and diversity of active CVE Numbering Authorities, system uptime and API performance, the share of records meeting defined quality criteria, and how often records require correction after publication. CISA sets no targets or deadlines for these metrics, presenting them only as potential indicators. The agency said technical modernization can make the program more consistent and scalable but can't replace community engagement, governance maturation, or shared expectations for vulnerability data.
The framework maps onto six lines of effort from CISA's existing CVE quality strategy, covering community partnerships, government sponsorship, modernization, transparency, data quality, and the program's CNA of Last Resort function. A blog series on cve.org in the coming months will detail infrastructure and data modernization work, and CISA said it will continue engaging CNAs, researchers, suppliers, and downstream data consumers. The agency's bottom line: the CVE program must shift from expanding quickly to operating reliably if it's going to serve a world where AI finds vulnerabilities faster than human-driven processes can keep up. Organizations that depend on timely, accurate CVE data for risk decisions will need to watch whether the framework's quality dimensions translate into measurable improvements, or whether the gap between discovery speed and record reliability continues to widen.

