CVE Board Meeting Minutes August 5, 2026 (2:00 p.m. –4:00 p.m. EDT) CVE Board Attendance ☐ Pete Allor ☐ Ken Armstrong, EWA – Canada, an Intertek Company<https://urldefense.us/v2/url?u=https-3A__www.intertek.com_cybersecurity_ewa-2Dcanada_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=3KbwG13m-lA0jt6f5gi1vg1P0Qd5V0KDeKexgB0gu7Q&e=> ☐ Tod Beardsley, Austin Hackers Anonymous<https://urldefense.us/v2/url?u=https-3A__takeonme.org_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=EhLxdIiW0NJ6T0QxGSO5mCZ3nPuOFZkG8au8GWCdEfw&e=> (AHA!) ☒ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency (CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=8ZeFzFn2x1Nf8F99MsUBWbsewaA3QMQ6-0Y5skF4Y-c&e=> ☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/> ☒ William Cox, Black Duck Software, Inc.<https://urldefense.us/v2/url?u=https-3A__www.blackduck.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=5lZlAgS0G3KXlbp2rLknUfoIWTS8k2l0RW5vYvwqVew&e=> ☒ Jen Ellis, NextJen Security<https://urldefense.us/v2/url?u=https-3A__uk.linkedin.com_in_infosecjen&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=choFXCWlp9BChebktC3f_Qt1gzT8nbltdOgyHJj3X7Y&e=> ☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency (CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=8ZeFzFn2x1Nf8F99MsUBWbsewaA3QMQ6-0Y5skF4Y-c&e=> ☐ Tim Keanini ☐ Kent Landfield ☒ Scott Lawler, LP3<https://urldefense.us/v2/url?u=https-3A__lp3.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=4Bop7ExHVZBtRsXBIvrMrTHi5vM2yZGG927miNdEoPA&e=> ☒ Art Manion ☒ MegaZone (CNA Board Liaison), F5, Inc.<https://urldefense.us/v2/url?u=https-3A__www.f5.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=tByelz_I_gvFewnXpkV1v5uKWqPMXS0xk3x5RFShrqM&e=> ☒ Tom Millar, Cybersecurity and Infrastructure Security Agency (CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=8ZeFzFn2x1Nf8F99MsUBWbsewaA3QMQ6-0Y5skF4Y-c&e=> ☐ Yogesh Mittal, Red Hat, Inc.<https://urldefense.us/v2/url?u=https-3A__www.redhat.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=YgOe83US3i3b5igYpZpemuTf2mwYpD5P0KdVx5IKS98&e=> ☒ Chandan Nandakumaraiah ☐ Kathleen Noble ☐ Madison Ficorilli, GitHub Security Lab<https://urldefense.us/v2/url?u=https-3A__securitylab.github.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=r3H3O4wgwAFLrSmzA2jMM8YufHl9oS9_avleMmO7ajo&e=> ☐ Lisa Olson, Microsoft<https://urldefense.us/v2/url?u=https-3A__www.microsoft.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=mHYMwue2xGVU5s6_vJYyhVkT4gjhqSnPKCPVezH7YB4&e=> ☐ Caroline D. Rosin, , NIST<https://urldefense.us/v2/url?u=https-3A__www.nist.gov_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=wD9gEEw_NavtyY3Jn-foSZ9pWqZzubYSkvzM3EF2Bl4&e=> ☐ Shannon Sabens, CrowdStrike, Inc.<https://urldefense.us/v2/url?u=https-3A__www.crowdstrike.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=r5Dr1sNE5RM_1AX3dbs4g-FXm51YM0hLgHT6i4JHAac&e=> ☒ Takayuki Uchiyama, Panasonic Holdings Corporation<https://urldefense.us/v2/url?u=https-3A__holdings.panasonic_global_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=dxfch9duU2JIpkRlTCJtmMQ6ImNI1kVuMCb835J6-s4&e=> ☐ David Waltermire ☒ James “Ken” Williams, Broadcom Inc.<https://urldefense.us/v2/url?u=https-3A__www.broadcom.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=2rWPj32IGskd6WUrZyagVLr0hWB-K-2JpJH5BJq1gbU&e=>
MITRE CVE Team Attendance ☒ Kris Britton ☒ Christine Deal ☐ Bob Roberge ☒ Anthony Singleton ☒ Jo Bazar ☒ Alec J Summers Agenda 1. CVE/CWE Bundling 2. AI Forum Discussion 3. Status Update: RBP and Inactive Policies 4. Frontier AI Researcher CNA Pilot 5. CNA Rules 4.2.0 6. Open Discussion New Action Items from Today’s Meeting New Action Item Responsible Party Initiate the proposed immediate interim solution for bundled CVE Records for downstream users’ situational awareness. Secretariat Develop action plan for bundling issue to assess prevalence and drivers and coordinate it with a visible community convening/workshopping effort. Board/Secretariat Open formal Board votes on the RBP and Inactive policy documents for one week, and on CNA Rules 4.2.0 for two weeks. Secretariat CVE/CWE Bundling The Secretariat summarized a recent discussion with a CNA about grouping multiple vulnerabilities into a single CVE Record. While the CNA cited increasing vulnerability volumes and operational efficiency as reasons for the approach, participants expressed concern that bundling can disrupt security tools and processes that rely on vulnerabilities being individually identifiable. Participants generally agreed that the CVE Program should reinforce its one-record-per-vulnerability model while carefully considering whether clearer requirements are needed. In the near term, the group discussed adding contextual information to affected records without discouraging remediation, with the proposed approach to be reviewed by the full Board. The Secretariat will share options for Board review and CNA engagement. Longer term, participants supported gathering input from the broader CNA community on rising vulnerability volumes, operational challenges, and potential Program support, alongside community discussions to identify practical solutions. ________________________________ AI Forum Discussion The Secretariat reported that notes from the recent virtual event on AI’s impact on vulnerability management were being finalized. The Secretariat is reviewing meeting chat alongside the presentations to capture community feedback and plans to conduct a follow-up survey with more targeted questions. Participants supported expanding the survey beyond event attendees and discussed including a carefully framed question on CVE bundling. Participants also noted that feedback on broader topics, such as record format and governance, could help inform future CVE Program priorities. The TWG will take action on post-event messaging. ________________________________ Status Update: RBP and Inactive Policies The Secretariat reported that the RBP and Inactive policy documents had been circulated for approximately three weeks with no additional feedback, and that prior redline comments had been addressed. Based on Board precedent, the group agreed the policy documents should proceed to formal approval. The policy vote will remain open for one week so the documents can be finalized and published promptly. ________________________________ Frontier AI Researcher CNA Pilot Participants noted that the pilot had been reviewed with the Board over several meetings and confirmed that it does not change any existing governance responsibilities. Members clarified that the pilot is a limited onboarding and evaluation approach for organizations with significant capability and potential scale. It does not change the CNA Operational Rules or requirements for existing CNAs, but establishes additional expectations for participating organizations. Feedback and operational experience will be tracked throughout the pilot via the GitHub repository issue tracker to evaluate participants against its commitments, identify lessons for future onboarding, and inform whether the piloting organizations should continue to hold researcher CNA scope beyond the pilot period. ________________________________ CNA Rules 4.2.0 The SPWG reported that the CNA Rules 4.2.0 package is ready for a Board vote. Feedback has been offered and incorporated, and supporting documents and issue history are available for Board review. The group agreed to use the normal two-week voting period for the rules. Because the RBP and Inactive policy votes and rules vote will run concurrently on different timelines, the Secretariat will clearly distinguish between the votes in Board communications. This document includes content generated with the assistance of Microsoft Teams Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the initial draft of the meeting minutes and provide suggestions for summarizing key discussion points. All AI-generated content has been reviewed and edited by the CVE Program prior to publishing. Please report any inaccuracies or other issues to the CVE Program.
