CVE Board Meeting Minutes July 22, 2026 (9:00 a.m. –11:00 a.m. EDT) CVE Board Attendance ☒ Pete Allor ☐ Ken Armstrong, EWA – Canada, an Intertek Company<https://www.intertek.com/cybersecurity/ewa-canada/> ☒ Tod Beardsley, Austin Hackers Anonymous<https://takeonme.org/> (AHA!) ☒ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency (CISA)<https://www.dhs.gov/cisa/cybersecurity-division/> ☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/> ☐ William Cox, Black Duck Software, Inc.<https://www.blackduck.com/> ☐ Jen Ellis, NextJen Security<https://uk.linkedin.com/in/infosecjen> ☒ Madison Ficorilli, GitHub Security Lab<https://securitylab.github.com/> ☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency (CISA)<https://www.dhs.gov/cisa/cybersecurity-division/> ☐ Tim Keanini ☐ Kent Landfield ☒ Scott Lawler, LP3<https://lp3.com/> ☐ Art Manion ☐ MegaZone (CNA Board Liaison), F5, Inc.<https://www.f5.com/> ☒ Tom Millar, Cybersecurity and Infrastructure Security Agency (CISA)<https://www.dhs.gov/cisa/cybersecurity-division/> ☒ Yogesh Mittal, Red Hat, Inc.<https://www.redhat.com/> ☒ Chandan Nandakumaraiah ☐ Kathleen Noble ☒ Lisa Olson, Microsoft<https://www.microsoft.com/> ☒ Caroline D. Rosin, NIST<https://www.nist.gov/> ☒ Shannon Sabens, CrowdStrike, Inc.<https://www.crowdstrike.com/> ☒ Takayuki Uchiyama, Panasonic Holdings Corporation<https://holdings.panasonic/global/> ☐ David Waltermire ☒ James “Ken” Williams, Broadcom Inc.<https://www.broadcom.com/>
MITRE CVE Team Attendance ☒ Kris Britton ☒ Christine Deal ☐ Bob Roberge ☒ Anthony Singleton ☐ Jo Bazar ☒ Alec J Summers Agenda 1. Proposed Updates to CNA Rules: Comments Received 2. CVE Program AI Forum: Draft Agenda 3. Frontier AI Researcher CNA Pilot Overview 4. Open Discussion New Action Items from Today’s Meeting New Action Item Responsible Party Finalize and circulate the July 30 CVE Program AI Forum agenda, including confirmed speakers, panelists, and final timing. Secretariat Hold a focused discussion on RBP publishing automation and workflow improvements, then update the Board on progress. Participating Board members Evaluate broader RBP visibility and reporting options, including automated notifications and statistical reporting to CNAs. Secretariat Proposed Updates to CNA Rules: Comments Received The community review period for the proposed CNA Rules updates ended on July 20. Because the topic lead was not present, the Board did not conduct a substantive review or make decisions on the comments received. Participants were directed to the open comment set for awareness. The Strategic Planning Working Group (SPWG) meeting for Wednesday, July 22, which was expected to review the comments, was also canceled. The rules discussion was therefore deferred for follow-up when the appropriate lead was available. ________________________________ CVE Program AI Forum: Draft Agenda The Secretariat provided an update on the virtual CVE Program AI Forum scheduled for July 30, 2026. Registration had reached 566 participants, and the agenda was nearing completion. The program was expected to include interactive data gathering, lightning talks, panel discussions representing perspectives across the CVE ecosystem, AI-enabled solutions, and identification of follow-on activities. The Board also discussed publishing a post-event recap through CVE Program channels. The Board noted that the agenda was at capacity but that several panel positions remained open. Members were encouraged to participate, with an emphasis on balanced representation across the ecosystem. The Board also agreed that video would not be required for panel participation and supported using a separate moderator for the concluding sessions. ________________________________ Frontier AI Researcher CNA Pilot Overview The Secretariat provided an update to the written overview of the proposed frontier AI researcher CNA pilot, developed following prior Board discussions on the opportunities and operational risks associated with onboarding frontier AI organizations with researcher CNA scope. The pilot would supplement, and not replace or modify, the CNA Operational Rules, which would continue to apply to participating CNAs. It would establish additional operating expectations to help the CVE Program evaluate high-scale vulnerability discovery while managing potential impacts related to validation, record quality, scope conflicts, coordinated disclosure, supplier coordination, remediation support, and broader ecosystem burden. The Board emphasized that participating CNAs would remain responsible for scope reconciliation and coordination, with the Top-Level Root providing governance and oversight. Participants also discussed improving CVE Record transfers between CNAs and developing guidance as transfer capabilities become more broadly available. The Board stressed the importance of providing maintainers with sufficient information and time to assess and remediate vulnerabilities, rather than generating high volumes of minimally validated findings. Scale, assignment velocity, duplicate or overlapping findings, and out-of-scope records were identified as key operational challenges. Participants noted that the effort is bounded and evaluative, and that lessons from the effort could inform whether participating CNAs should retain researcher scope and whether broader CVE Program practices should evolve as AI-assisted vulnerability research becomes more common. ________________________________ Open Discussion Reserved but Public (RBP) CVEs The Board discussed improving visibility into CVE IDs that remain Reserved after vulnerability information becomes public. Participants supported an approach focused on helping CNAs identify and address these records, including renewed reporting or automated notifications. The Board discussed using automation and external vulnerability sources to identify potential RBPs while recognizing that the assigning CNA remains responsible for authoritative CVE record information. Participants also considered potential metadata and workflow improvements but noted verification, engineering, and workload challenges. The discussion highlighted publication backlogs and increasing demand among high-volume CNAs. Participants agreed to compare existing publication workflows and automation approaches, while the Secretariat will consider options to improve RBP reporting and notifications. VulnCon 2027 Dates Participants confirmed that VulnCon 2027 has been moved one week earlier to avoid a conflict with RSA Conference. The dates shared in the meeting chat were March 30–April 2, 2027. This document includes content generated with the assistance of Microsoft Teams Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the initial draft of the meeting minutes and provide suggestions for summarizing key discussion points. All AI-generated content has been reviewed and edited by the CVE Program prior to publishing. Please report any inaccuracies or other issues to the CVE Program.
