CISA Ensures Ongoing Backing for CVE Program, Denies Budget Issues

CISA Reaffirms Full Support for CVE Program Amid Contract Concerns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has firmly reiterated its commitment to the Common Vulnerabilities and Exposures (CVE) Program, dispelling recent reports suggesting the initiative was at risk due to funding issues.

According to CISA, there was never a budgetary crisis. Instead, a contract administration hiccup briefly raised concerns but was swiftly resolved without causing any service disruption. The agency emphasized that the CVE Program has continued to operate seamlessly throughout.

Operated by MITRE with CISA as its long-time sponsor, the CVE Program is a fundamental component of global cybersecurity. It provides a standardized framework for identifying and cataloging publicly known software vulnerabilities—an essential tool for network defenders, developers, and security researchers working to address threats efficiently and consistently.

“We are proud to sponsor the CVE program—an invaluable public resource relied upon by network defenders and software developers alike. We are fully committed to sustaining and improving this critical cyber infrastructure.”
Cybersecurity and Infrastructure Security Agency (@CISAgov), April 24, 2025

Concerns emerged after MITRE warned that its federal contract to manage the program would expire on April 16, 2025. The cybersecurity community quickly raised alarms about the possible disruption such a lapse could cause.

In response, CISA moved decisively, exercising an option to extend the contract just hours before the deadline. The result: an uninterrupted 11-month continuation of services and a clear signal of the agency’s unwavering support.

“The CVE Program is invaluable to the cyber community and a priority of CISA,” a spokesperson said, reaffirming the agency’s commitment to maintaining and advancing the initiative.

Under CISA’s guidance, the CVE Program has evolved into a global, federated system. Working in partnership with MITRE and the CVE Board, it now includes 453 CVE Numbering Authorities (CNAs) worldwide. This decentralized approach enables faster identification and dissemination of vulnerability information, strengthening global response capabilities.

CISA also acknowledges that the program must keep evolving. The agency is actively collaborating with MITRE, the CVE Board, and the broader cybersecurity community to refine strategies, gather feedback, and improve transparency.

Looking forward, efforts are focused on broadening participation, increasing international collaboration, and ensuring that the CVE Program remains both stable and innovative. These initiatives are key to securing its future as a global public good.

Through recent actions and strong public assurances, CISA has underscored its top priority: preserving and enhancing the CVE Program as a vital resource for protecting digital infrastructure worldwide.

More Articles & Posts