CVE Board Meeting Minutes
July 22, 2026 (9:00 a.m. –11:00 a.m. EDT)

CVE Board Attendance
☒ Pete Allor
☐ Ken Armstrong, EWA – Canada, an Intertek 
Company<https://www.intertek.com/cybersecurity/ewa-canada/>
☒ Tod Beardsley, Austin Hackers Anonymous<https://takeonme.org/> (AHA!)
☒ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/>
☐ William Cox, Black Duck Software, Inc.<https://www.blackduck.com/>
☐ Jen Ellis, NextJen Security<https://uk.linkedin.com/in/infosecjen>
☒ Madison Ficorilli, GitHub Security Lab<https://securitylab.github.com/>
☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☐ Tim Keanini
☐ Kent Landfield
☒ Scott Lawler, LP3<https://lp3.com/>
☐ Art Manion
☐ MegaZone (CNA Board Liaison), F5, Inc.<https://www.f5.com/>
☒ Tom Millar, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☒ Yogesh Mittal, Red Hat, Inc.<https://www.redhat.com/>
☒ Chandan Nandakumaraiah
☐ Kathleen Noble
☒ Lisa Olson, Microsoft<https://www.microsoft.com/>
☒ Caroline D. Rosin, NIST<https://www.nist.gov/>
☒ Shannon Sabens, CrowdStrike, Inc.<https://www.crowdstrike.com/>
☒ Takayuki Uchiyama, Panasonic Holdings 
Corporation<https://holdings.panasonic/global/>
☐ David Waltermire
☒ James “Ken” Williams, Broadcom Inc.<https://www.broadcom.com/>


MITRE CVE Team Attendance
☒ Kris Britton
☒ Christine Deal
☐ Bob Roberge
☒ Anthony Singleton
☐ Jo Bazar
☒ Alec J Summers

Agenda


  1.  Proposed Updates to CNA Rules: Comments Received
  2.  CVE Program AI Forum: Draft Agenda
  3.  Frontier AI Researcher CNA Pilot Overview
  4.  Open Discussion

New Action Items from Today’s Meeting
New Action Item

Responsible Party

Finalize and circulate the July 30 CVE Program AI Forum agenda, including 
confirmed speakers, panelists, and final timing.
Secretariat
Hold a focused discussion on RBP publishing automation and workflow 
improvements, then update the Board on progress.
Participating Board members
Evaluate broader RBP visibility and reporting options, including automated 
notifications and statistical reporting to CNAs.
Secretariat

Proposed Updates to CNA Rules: Comments Received
The community review period for the proposed CNA Rules updates ended on July 
20. Because the topic lead was not present, the Board did not conduct a 
substantive review or make decisions on the comments received. Participants 
were directed to the open comment set for awareness.
The Strategic Planning Working Group (SPWG) meeting for Wednesday, July 22, 
which was expected to review the comments, was also canceled. The rules 
discussion was therefore deferred for follow-up when the appropriate lead was 
available.
________________________________
CVE Program AI Forum: Draft Agenda
The Secretariat provided an update on the virtual CVE Program AI Forum 
scheduled for July 30, 2026. Registration had reached 566 participants, and the 
agenda was nearing completion.
The program was expected to include interactive data gathering, lightning 
talks, panel discussions representing perspectives across the CVE ecosystem, 
AI-enabled solutions, and identification of follow-on activities. The Board 
also discussed publishing a post-event recap through CVE Program channels.
The Board noted that the agenda was at capacity but that several panel 
positions remained open. Members were encouraged to participate, with an 
emphasis on balanced representation across the ecosystem.
The Board also agreed that video would not be required for panel participation 
and supported using a separate moderator for the concluding sessions.
________________________________
Frontier AI Researcher CNA Pilot Overview
The Secretariat provided an update to the written overview of the proposed 
frontier AI researcher CNA pilot, developed following prior Board discussions 
on the opportunities and operational risks associated with onboarding frontier 
AI organizations with researcher CNA scope. The pilot would supplement, and not 
replace or modify, the CNA Operational Rules, which would continue to apply to 
participating CNAs. It would establish additional operating expectations to 
help the CVE Program evaluate high-scale vulnerability discovery while managing 
potential impacts related to validation, record quality, scope conflicts, 
coordinated disclosure, supplier coordination, remediation support, and broader 
ecosystem burden.
The Board emphasized that participating CNAs would remain responsible for scope 
reconciliation and coordination, with the Top-Level Root providing governance 
and oversight. Participants also discussed improving CVE Record transfers 
between CNAs and developing guidance as transfer capabilities become more 
broadly available.
The Board stressed the importance of providing maintainers with sufficient 
information and time to assess and remediate vulnerabilities, rather than 
generating high volumes of minimally validated findings. Scale, assignment 
velocity, duplicate or overlapping findings, and out-of-scope records were 
identified as key operational challenges.
Participants noted that the effort is bounded and evaluative, and that lessons 
from the effort could inform whether participating CNAs should retain 
researcher scope and whether broader CVE Program practices should evolve as 
AI-assisted vulnerability research becomes more common.
________________________________
Open Discussion
Reserved but Public (RBP) CVEs
The Board discussed improving visibility into CVE IDs that remain Reserved 
after vulnerability information becomes public. Participants supported an 
approach focused on helping CNAs identify and address these records, including 
renewed reporting or automated notifications.
The Board discussed using automation and external vulnerability sources to 
identify potential RBPs while recognizing that the assigning CNA remains 
responsible for authoritative CVE record information. Participants also 
considered potential metadata and workflow improvements but noted verification, 
engineering, and workload challenges.
The discussion highlighted publication backlogs and increasing demand among 
high-volume CNAs. Participants agreed to compare existing publication workflows 
and automation approaches, while the Secretariat will consider options to 
improve RBP reporting and notifications.

VulnCon 2027 Dates
Participants confirmed that VulnCon 2027 has been moved one week earlier to 
avoid a conflict with RSA Conference. The dates shared in the meeting chat were 
March 30–April 2, 2027.

This document includes content generated with the assistance of Microsoft Teams 
Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the 
initial draft of the meeting minutes and provide suggestions for summarizing 
key discussion points. All AI-generated content has been reviewed and edited by 
the CVE Program prior to publishing. Please report any inaccuracies or other 
issues to the CVE Program.

Reply via email to