The National Institute of Standards and Technology (NIST) is undertaking a significant overhaul of how it manages the Common Vulnerabilities and Exposures (CVE) program, a move driven by the unprecedented surge in vulnerability disclosures worldwide. As cyber threats grow in volume and complexity, NIST’s updated workflows aim to improve the speed, accuracy and usability of vulnerability data for organizations tasked with patching and remediation. The changes, announced in early 2024, represent one of the most substantial shifts in the CVE program’s structure since its inception, affecting how vulnerabilities are identified, categorized, and disseminated across global cybersecurity ecosystems.
For years, the CVE system has served as the cornerstone of vulnerability management, providing a standardized way to identify and track software flaws. However, the exponential rise in reported vulnerabilities—exceeding 29,000 in 2023 alone, according to MITRE Corporation—has strained the existing infrastructure. NIST, which assumed administrative oversight of the CVE program in 2023 under a cooperative agreement with The MITRE Corporation, says the current model struggles to keep pace with demand, leading to delays in vulnerability publication and inconsistencies in scoring and classification.
“The volume of vulnerabilities being reported has outgrown the legacy processes,” said a NIST spokesperson in a February 2024 briefing. “We need a system that is more agile, transparent, and responsive to the needs of both vulnerability reporters and downstream consumers like software vendors, enterprise IT teams, and government agencies.” The initiative, dubbed the CVE Program Modernization Effort, focuses on streamlining intake, enhancing metadata tagging, and improving integration with the National Vulnerability Database (NVD), which NIST also manages.
One of the core changes involves replacing the legacy CVE Numbering Authorities (CNAs) root system with a more decentralized, federated model designed to increase scalability. Under the new structure, approved organizations can request direct CVE ID allocation through automated systems, reducing reliance on manual review bottlenecks. NIST says this shift will help accommodate the growing number of CNAs—now exceeding 300 globally—and support faster assignment of identifiers, particularly for high-volume reporters like major technology firms and open-source projects.
Another key update is the introduction of standardized enrichment fields in CVE records, including improved classification of vulnerability types using the Common Weakness Enumeration (CWE) framework and more consistent mapping to the Common Attack Pattern Enumeration and Classification (CAPEC). These enhancements aim to give security teams better context for prioritizing fixes, especially when dealing with complex chains of flaws or zero-day exploits. NIST plans to roll out these enriched fields gradually, beginning with a pilot program involving select CNAs in mid-2024.
The modernization also includes upgrades to the CVE website and application programming interface (API), making machine-readable data more accessible for automation in security orchestration, automation, and response (SOAR) tools and vulnerability management platforms. Improved API rate limits, better documentation, and enhanced filtering capabilities are expected to reduce the burden on security analysts who currently spend significant time parsing raw CVE feeds.
Industry experts say the changes could have far-reaching implications for how organizations approach vulnerability remediation. “Faster, more reliable CVE data means security teams can act sooner,” said Jen Ellis, vice president of community and public affairs at Rapid7. “But it also means they need to be ready to handle a higher velocity of alerts. The real challenge won’t be getting the data—it’ll be acting on it effectively.” Ellis emphasized that even as NIST’s improvements are welcome, organizations must still invest in prioritization frameworks like risk-based vulnerability management (RBVM) to avoid alert fatigue.
The timing of the overhaul coincides with increased federal focus on software supply chain security. In 2023, the White House issued Executive Order 14028, which mandated stronger vulnerability disclosure practices and called for greater transparency in federal software procurement. NIST’s updated CVE workflows align with these goals by improving traceability and accountability in the vulnerability lifecycle. The agency says it will continue to collaborate with the Cybersecurity and Infrastructure Security Agency (CISA) to ensure the changes support national cybersecurity objectives.
Transparency and stakeholder engagement are central to the modernization effort. NIST has launched a public feedback portal where researchers, vendors, and end-users can submit comments on proposed changes. The agency has also committed to publishing quarterly progress reports detailing milestones, adoption rates, and any encountered challenges. As of April 2024, over 120 organizations have participated in the feedback process, with many praising the direction while urging caution against disrupting existing integrations during the transition.
Despite the optimism, some concerns remain about potential fragmentation. Critics warn that decentralizing CNA authority without sufficient oversight could lead to inconsistencies in how vulnerabilities are described or scored. NIST counters that it will maintain strict compliance requirements for all CNAs and conduct regular audits to ensure data quality. The agency also plans to retain a centralized quality review function for high-impact vulnerabilities, particularly those affecting critical infrastructure or widely deployed software.
Looking ahead, NIST says the next major milestone is the planned release of the updated CVE JSON schema version 5.0 in late 2024, which will formalize the new data structure and support the enriched fields. A public webinar to walk through the changes is scheduled for June 18, 2024, with registration available via the NIST website. Until then, the current CVE and NVD systems will continue operating in parallel, with no disruption to existing services expected during the transition period.
As the digital attack surface expands and vulnerability reporting becomes more democratized, the ability to process and act on security data swiftly is no longer optional—it’s essential. NIST’s efforts to modernize the CVE program reflect a broader recognition that cybersecurity resilience depends not just on detecting flaws, but on making that information usable, timely, and trustworthy across the entire ecosystem. For security professionals navigating an increasingly complex threat landscape, these changes could mean the difference between staying ahead of threats and constantly playing catch-up.
For the latest updates on the CVE program modernization, including access to the public feedback portal and upcoming webinar details, visit the NIST Computer Security Division’s official page on the CVE initiative.
We welcome your thoughts on how these changes might affect your organization’s vulnerability management practices. Share your experiences in the comments below, and consider sharing this article with colleagues who rely on CVE data to keep their systems secure.
Related reading