CVE Board Meeting Minutes
June 24, 2026 (9:00 a.m. – 11:00 a.m. EDT)

CVE Board Attendance
☐ Pete Allor
☐ Ken Armstrong, EWA – Canada, an Intertek 
Company<https://www.intertek.com/cybersecurity/ewa-canada/>
☐ Tod Beardsley, Austin Hackers Anonymous<https://takeonme.org/> (AHA!)
☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/>
☒ William Cox, Black Duck Software, Inc.<https://www.blackduck.com/>
☒ Jen Ellis, NextJen Security<https://uk.linkedin.com/in/infosecjen>
☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☐ Tim Keanini
☐ Kent Landfield
☒ Scott Lawler, LP3<https://lp3.com/>
☒ Art Manion
☒ MegaZone (CNA Board Liaison), F5, Inc.<https://www.f5.com/>
☒ Tom Millar, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☒ Yogesh Mittal, Red Hat, Inc.<https://www.redhat.com/>
☒ Chandan Nandakumaraiah
☐ Kathleen Noble
☒ Madison Ficorilli, GitHub Security Lab<https://securitylab.github.com/>
☒ Lisa Olson, Microsoft<https://www.microsoft.com/>
☒ Shannon Sabens, CrowdStrike, Inc.<https://www.crowdstrike.com/>
☒ Takayuki Uchiyama, Panasonic Holdings 
Corporation<https://holdings.panasonic/global/>
☐ David Waltermire
☒ James “Ken” Williams, Broadcom Inc.<https://www.broadcom.com/>

MITRE CVE Team Attendance
☐ Kris Britton
☐ Christine Deal
☐ Bob Roberge
☒ Anthony Singleton
☒ Jo Bazar
☒ Alec J Summers
☒ Jeremy Daigneau

Agenda

  1.  SPWG Proposed CNA Rules Changes
  2.  Community Ecosystem AI Discussion (July 30th, 10:00 a.m.–2:00 p.m. EDT)
  3.  CPE Workshop Readout (June 22, 2026)
  4.  Open Discussion — Draft RBP and Inactive Policy

New Action Items from Today’s Meeting
New Action Item

Responsible Party

Prepare the proposed CNA Operational Rules change document for broader program 
review, including the Google Doc and related GitHub issues, and incorporate any 
final cleanup needed before circulation and send to Secretariat for 
distribution to CVE Board review and CNA list.
SPWG
Announce the proposed CNA Operational Rules changes to the CNA list, include 
links to the Google Doc and GitHub issues, and open a two-week program review 
period before Board review and any vote.
Secretariat
Collect and adjudicate feedback on the proposed CNA Operational Rules changes, 
then schedule Board review and a potential vote.
Board/Secretariat/SPWG
Continue building the agenda for the July 30 virtual event, including 
soliciting discussion leaders, speakers, community-submitted topics, and input 
from relevant external organizations.
TWG/Board
Share or circulate NIST CPE workshop contact information and materials when 
available and continue tracking NIST next steps on CPE 3.0 feedback.
Board/Secretariat
Launch a 2-week review period for the updated RBP and inactive CNA policies.
Board/Secretariat

SPWG Proposed CNA Rules Changes
The CVE Program continues work to improve the CNA Operational Rules with the 
goals of increasing clarity, consistency, and usability for participating CVE 
Numbering Authorities (CNAs).
One area of clarification addresses the requirement for CNAs to provide an 
unencumbered path for CVE ID assignment requests. The updated guidance is 
intended to ensure that organizations requesting CVE IDs can do so without 
accepting terms that would restrict vulnerability disclosure, communication, or 
other CVE Program activities. Organizations may continue to operate bug bounty 
programs or coordinated vulnerability disclosure processes with their own 
terms, provided there is also a path for CVE ID requests that does not impose 
conflicting restrictions.
The SPWG’s proposals also refined guidance related to insecure default 
configurations. Because vulnerability determination in this area often depends 
on factors such as documentation, user expectations, threat models, and whether 
a default configuration directly enables exploitation, the guidance aims to 
improve consistency while recognizing that some degree of technical judgment 
remains necessary.
In addition, participants identified opportunities to make the CNA Operational 
Rules easier to use. Ideas include more clearly distinguishing mandatory 
requirements from implementation guidance, improving document organization, and 
exploring supporting materials such as flow charts, tables, or other 
navigational aids to help CNAs apply the rules more consistently.
The proposed updates will be shared with the broader CNA community for review 
and feedback before being finalized.

Community Ecosystem AI Discussion (July 30th 10am-2pm EDT)
The Board received an update on planning for the July 30 virtual event, CVE in 
an Era of AI-Enabled Vulnerability Discovery, which will be held from 10:00 
a.m. to 2:00 p.m. EDT. Registration is strong, and planning continues to focus 
on developing the agenda and identifying discussion leaders and speakers. The 
agenda is expected to draw on perspectives from across the vulnerability 
management ecosystem, with community input being collected through an open 
issue tracker to help shape the discussion.

CPE Workshop Readout (June 22, 2026)
The Board received a readout from the June 22 NIST workshop on CPE. The 
workshop covered future design directions for CPE, including possible changes 
for CPE 3.0, hardware support, and severity-related topics such as CVSS and 
SSVC.

The CPE 3.0 discussion included proposals such as moving toward opaque 
identifiers, separating identifiers from metadata, establishing metadata 
libraries, and potentially using a federated model in which CNAs or product 
owners could contribute or control product-identification data. Participants 
noted changes could be backwardly incompatible, while NIST also appeared 
interested in preserving the value of existing product information and 
applicability statements where feasible.
The workshop also addressed hardware-identification challenges. Participants 
noted that CPE is not generally used for hardware today and that some hardware 
vendors may not find current CPE mechanisms useful. The Board discussed that 
any CPE 3.0 changes must balance more useful product identification with the 
practical question of whether hardware vendors and other ecosystem participants 
will adopt the new model.

________________________________
Open Discussion
Revised RBP and Inactive CNA Policies
The Secretariat noted that revised RBP and Inactive CNA policies were sent to 
the CVE Board for review on June 23rd. Both policies have been reviewed and 
vetted by the Council of Roots, TWG and SPWG. The revised policies are intended 
to provide flexibility for Top-Level Roots and Roots to set appropriate time 
frames and remediation processes while preserving a common program-wide 
approach. The Board discussed launching a 2- week review period by the CNAs and 
then the CVE Board before the policies are implemented.

This document includes content generated with the assistance of Microsoft Teams 
Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the 
initial draft of the meeting minutes and provide suggestions for summarizing 
key discussion points. All AI-generated content has been reviewed and edited by 
the CVE Program prior to publishing. Please report any inaccuracies or other 
issues to the CVE Program.

Reply via email to