CVE Board Meeting Minutes
July 8, 2026 (2:00 p.m. –4:00 p.m. EDT)

CVE Board Attendance
☒ Pete Allor
☐ Ken Armstrong, EWA – Canada, an Intertek 
Company<https://www.intertek.com/cybersecurity/ewa-canada/>
☒ Tod Beardsley, Austin Hackers Anonymous<https://takeonme.org/> (AHA!)
☐ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/>
☐ William Cox, Black Duck Software, Inc.<https://www.blackduck.com/>
☐ Jen Ellis, NextJen Security<https://uk.linkedin.com/in/infosecjen>
☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☐ Tim Keanini
☐ Kent Landfield
☒ Scott Lawler, LP3<https://lp3.com/>
☒ Art Manion
☒ MegaZone (CNA Board Liaison), F5, Inc.<https://www.f5.com/>
☒ Tom Millar, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://www.dhs.gov/cisa/cybersecurity-division/>
☒ Yogesh Mittal, Red Hat, Inc.<https://www.redhat.com/>
☒ Chandan Nandakumaraiah
☒ Kathleen Noble
☒ Madison Ficorilli, GitHub Security Lab<https://securitylab.github.com/>
☒ Lisa Olson, Microsoft<https://www.microsoft.com/>
☒ Shannon Sabens, CrowdStrike, Inc.<https://www.crowdstrike.com/>
☒ Caroline Rosin, NIST<https://www.nist.gov/>
☒ Takayuki Uchiyama, Panasonic Holdings 
Corporation<https://holdings.panasonic/global/>
☒ David Waltermire
☒ James “Ken” Williams, Broadcom Inc.<https://www.broadcom.com/>


MITRE CVE Team Attendance
☒ Kris Britton
☒ Christine Deal
☐ Bob Roberge
☒ Anthony Singleton
☒ Jo Bazar
☒ Alec J Summers


Agenda

  1.  TWG Report - Agenda for AI Forum
  2.  Add a CVE Triage Checklist to the CNA Rules
  3.  (S)ADP Status and Discussion

New Action Items from Today’s Meeting
New Action Item

Responsible Party

Update the draft AI Forum agenda to reflect the current structure: guided 
listening sessions at the beginning and end, lightning talks in the middle, and 
a clear kickoff/readout approach.
TWG
Recruit and schedule volunteers for AI Forum lightning talks and 
listening-session facilitation, including outreach through Board and community 
networks.
TWG
Determine whether Mentimeter or a similar interactive tool requires a paid 
account for the expected AI Forum audience size and report back.
TWG

TWG Report: Agenda for CVE Program Virtual Forum (AI-Enabled Vulnerability 
Discovery)
The Board received an update on planning for the July 30 virtual AI Forum. The 
event is being designed as an interactive community discussion featuring 
listening sessions, lightning talks, and opportunities to identify actionable 
outcomes for the CVE Program and the broader vulnerability management ecosystem.
Board members were encouraged to participate as speakers or facilitators and to 
help promote the event within their communities.
________________________________
Add a CVE Triage Checklist to the CNA Rules
The Board discussed a proposed checklist intended to make the CNA Rules easier 
to use without changing their requirements. Participants also discussed 
additional supporting materials, such as flow charts and companion documents, 
to improve usability while recognizing that some complexity reflects the 
operational needs of the program.
The Board supported continued work on the checklist and discussed approaches 
for maintaining future rules guidance and managing updates to the CNA Rules.

This document includes content generated with the assistance of Microsoft Teams 
Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the 
initial draft of the meeting minutes and provide suggestions for summarizing 
key discussion points. All AI-generated content has been reviewed and edited by 
the CVE Program prior to publishing. Please report any inaccuracies or other 
issues to the CVE Program.

Reply via email to