CVE Board Meeting Minutes June 24, 2026 (9:00 a.m. – 11:00 a.m. EDT) CVE Board Attendance ☐ Pete Allor ☐ Ken Armstrong, EWA – Canada, an Intertek Company<https://www.intertek.com/cybersecurity/ewa-canada/> ☐ Tod Beardsley, Austin Hackers Anonymous<https://takeonme.org/> (AHA!) ☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/> ☒ William Cox, Black Duck Software, Inc.<https://www.blackduck.com/> ☒ Jen Ellis, NextJen Security<https://uk.linkedin.com/in/infosecjen> ☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency (CISA)<https://www.dhs.gov/cisa/cybersecurity-division/> ☐ Tim Keanini ☐ Kent Landfield ☒ Scott Lawler, LP3<https://lp3.com/> ☒ Art Manion ☒ MegaZone (CNA Board Liaison), F5, Inc.<https://www.f5.com/> ☒ Tom Millar, Cybersecurity and Infrastructure Security Agency (CISA)<https://www.dhs.gov/cisa/cybersecurity-division/> ☒ Yogesh Mittal, Red Hat, Inc.<https://www.redhat.com/> ☒ Chandan Nandakumaraiah ☐ Kathleen Noble ☒ Madison Ficorilli, GitHub Security Lab<https://securitylab.github.com/> ☒ Lisa Olson, Microsoft<https://www.microsoft.com/> ☒ Shannon Sabens, CrowdStrike, Inc.<https://www.crowdstrike.com/> ☒ Takayuki Uchiyama, Panasonic Holdings Corporation<https://holdings.panasonic/global/> ☐ David Waltermire ☒ James “Ken” Williams, Broadcom Inc.<https://www.broadcom.com/>
MITRE CVE Team Attendance ☐ Kris Britton ☐ Christine Deal ☐ Bob Roberge ☒ Anthony Singleton ☒ Jo Bazar ☒ Alec J Summers ☒ Jeremy Daigneau Agenda 1. SPWG Proposed CNA Rules Changes 2. Community Ecosystem AI Discussion (July 30th, 10:00 a.m.–2:00 p.m. EDT) 3. CPE Workshop Readout (June 22, 2026) 4. Open Discussion — Draft RBP and Inactive Policy New Action Items from Today’s Meeting New Action Item Responsible Party Prepare the proposed CNA Operational Rules change document for broader program review, including the Google Doc and related GitHub issues, and incorporate any final cleanup needed before circulation and send to Secretariat for distribution to CVE Board review and CNA list. SPWG Announce the proposed CNA Operational Rules changes to the CNA list, include links to the Google Doc and GitHub issues, and open a two-week program review period before Board review and any vote. Secretariat Collect and adjudicate feedback on the proposed CNA Operational Rules changes, then schedule Board review and a potential vote. Board/Secretariat/SPWG Continue building the agenda for the July 30 virtual event, including soliciting discussion leaders, speakers, community-submitted topics, and input from relevant external organizations. TWG/Board Share or circulate NIST CPE workshop contact information and materials when available and continue tracking NIST next steps on CPE 3.0 feedback. Board/Secretariat Launch a 2-week review period for the updated RBP and inactive CNA policies. Board/Secretariat SPWG Proposed CNA Rules Changes The CVE Program continues work to improve the CNA Operational Rules with the goals of increasing clarity, consistency, and usability for participating CVE Numbering Authorities (CNAs). One area of clarification addresses the requirement for CNAs to provide an unencumbered path for CVE ID assignment requests. The updated guidance is intended to ensure that organizations requesting CVE IDs can do so without accepting terms that would restrict vulnerability disclosure, communication, or other CVE Program activities. Organizations may continue to operate bug bounty programs or coordinated vulnerability disclosure processes with their own terms, provided there is also a path for CVE ID requests that does not impose conflicting restrictions. The SPWG’s proposals also refined guidance related to insecure default configurations. Because vulnerability determination in this area often depends on factors such as documentation, user expectations, threat models, and whether a default configuration directly enables exploitation, the guidance aims to improve consistency while recognizing that some degree of technical judgment remains necessary. In addition, participants identified opportunities to make the CNA Operational Rules easier to use. Ideas include more clearly distinguishing mandatory requirements from implementation guidance, improving document organization, and exploring supporting materials such as flow charts, tables, or other navigational aids to help CNAs apply the rules more consistently. The proposed updates will be shared with the broader CNA community for review and feedback before being finalized. Community Ecosystem AI Discussion (July 30th 10am-2pm EDT) The Board received an update on planning for the July 30 virtual event, CVE in an Era of AI-Enabled Vulnerability Discovery, which will be held from 10:00 a.m. to 2:00 p.m. EDT. Registration is strong, and planning continues to focus on developing the agenda and identifying discussion leaders and speakers. The agenda is expected to draw on perspectives from across the vulnerability management ecosystem, with community input being collected through an open issue tracker to help shape the discussion. CPE Workshop Readout (June 22, 2026) The Board received a readout from the June 22 NIST workshop on CPE. The workshop covered future design directions for CPE, including possible changes for CPE 3.0, hardware support, and severity-related topics such as CVSS and SSVC. The CPE 3.0 discussion included proposals such as moving toward opaque identifiers, separating identifiers from metadata, establishing metadata libraries, and potentially using a federated model in which CNAs or product owners could contribute or control product-identification data. Participants noted changes could be backwardly incompatible, while NIST also appeared interested in preserving the value of existing product information and applicability statements where feasible. The workshop also addressed hardware-identification challenges. Participants noted that CPE is not generally used for hardware today and that some hardware vendors may not find current CPE mechanisms useful. The Board discussed that any CPE 3.0 changes must balance more useful product identification with the practical question of whether hardware vendors and other ecosystem participants will adopt the new model. ________________________________ Open Discussion Revised RBP and Inactive CNA Policies The Secretariat noted that revised RBP and Inactive CNA policies were sent to the CVE Board for review on June 23rd. Both policies have been reviewed and vetted by the Council of Roots, TWG and SPWG. The revised policies are intended to provide flexibility for Top-Level Roots and Roots to set appropriate time frames and remediation processes while preserving a common program-wide approach. The Board discussed launching a 2- week review period by the CNAs and then the CVE Board before the policies are implemented. This document includes content generated with the assistance of Microsoft Teams Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the initial draft of the meeting minutes and provide suggestions for summarizing key discussion points. All AI-generated content has been reviewed and edited by the CVE Program prior to publishing. Please report any inaccuracies or other issues to the CVE Program.
