CVE Board Meeting Minutes
August 5, 2026 (2:00 p.m. –4:00 p.m. EDT)

CVE Board Attendance
☐ Pete Allor
☐ Ken Armstrong, EWA – Canada, an Intertek 
Company<https://urldefense.us/v2/url?u=https-3A__www.intertek.com_cybersecurity_ewa-2Dcanada_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=3KbwG13m-lA0jt6f5gi1vg1P0Qd5V0KDeKexgB0gu7Q&e=>
☐ Tod Beardsley, Austin Hackers 
Anonymous<https://urldefense.us/v2/url?u=https-3A__takeonme.org_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=EhLxdIiW0NJ6T0QxGSO5mCZ3nPuOFZkG8au8GWCdEfw&e=>
 (AHA!)
☒ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=8ZeFzFn2x1Nf8F99MsUBWbsewaA3QMQ6-0Y5skF4Y-c&e=>
☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/>
☒ William Cox, Black Duck Software, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.blackduck.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=5lZlAgS0G3KXlbp2rLknUfoIWTS8k2l0RW5vYvwqVew&e=>
☒ Jen Ellis, NextJen 
Security<https://urldefense.us/v2/url?u=https-3A__uk.linkedin.com_in_infosecjen&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=choFXCWlp9BChebktC3f_Qt1gzT8nbltdOgyHJj3X7Y&e=>
☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=8ZeFzFn2x1Nf8F99MsUBWbsewaA3QMQ6-0Y5skF4Y-c&e=>
☐ Tim Keanini
☐ Kent Landfield
☒ Scott Lawler, 
LP3<https://urldefense.us/v2/url?u=https-3A__lp3.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=4Bop7ExHVZBtRsXBIvrMrTHi5vM2yZGG927miNdEoPA&e=>
☒ Art Manion
☒ MegaZone (CNA Board Liaison), F5, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.f5.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=tByelz_I_gvFewnXpkV1v5uKWqPMXS0xk3x5RFShrqM&e=>
☒ Tom Millar, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=8ZeFzFn2x1Nf8F99MsUBWbsewaA3QMQ6-0Y5skF4Y-c&e=>
☐ Yogesh Mittal, Red Hat, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.redhat.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=YgOe83US3i3b5igYpZpemuTf2mwYpD5P0KdVx5IKS98&e=>
☒ Chandan Nandakumaraiah
☐ Kathleen Noble
☐ Madison Ficorilli, GitHub Security 
Lab<https://urldefense.us/v2/url?u=https-3A__securitylab.github.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=r3H3O4wgwAFLrSmzA2jMM8YufHl9oS9_avleMmO7ajo&e=>
☐ Lisa Olson, 
Microsoft<https://urldefense.us/v2/url?u=https-3A__www.microsoft.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=mHYMwue2xGVU5s6_vJYyhVkT4gjhqSnPKCPVezH7YB4&e=>
☐ Caroline D. Rosin, , 
NIST<https://urldefense.us/v2/url?u=https-3A__www.nist.gov_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=wD9gEEw_NavtyY3Jn-foSZ9pWqZzubYSkvzM3EF2Bl4&e=>
☐ Shannon Sabens, CrowdStrike, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.crowdstrike.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=r5Dr1sNE5RM_1AX3dbs4g-FXm51YM0hLgHT6i4JHAac&e=>
☒ Takayuki Uchiyama, Panasonic Holdings 
Corporation<https://urldefense.us/v2/url?u=https-3A__holdings.panasonic_global_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=dxfch9duU2JIpkRlTCJtmMQ6ImNI1kVuMCb835J6-s4&e=>
☐ David Waltermire
☒ James “Ken” Williams, Broadcom 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.broadcom.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=wSiRov5W6dDe2t26OfJrCka8rD4sLgQJc00S3sau57Fo-Is-1J3IUnmHZfBwNVHm&s=2rWPj32IGskd6WUrZyagVLr0hWB-K-2JpJH5BJq1gbU&e=>


MITRE CVE Team Attendance
☒ Kris Britton
☒ Christine Deal
☐ Bob Roberge
☒ Anthony Singleton
☒ Jo Bazar
☒ Alec J Summers

Agenda


  1.  CVE/CWE Bundling
  2.  AI Forum Discussion
  3.  Status Update: RBP and Inactive Policies
  4.  Frontier AI Researcher CNA Pilot
  5.  CNA Rules 4.2.0
  6.  Open Discussion

New Action Items from Today’s Meeting
New Action Item

Responsible Party

Initiate the proposed immediate interim solution for bundled CVE Records for 
downstream users’ situational awareness.
Secretariat
Develop action plan for bundling issue to assess prevalence and drivers and 
coordinate it with a visible community convening/workshopping effort.
Board/Secretariat
Open formal Board votes on the RBP and Inactive policy documents for one week, 
and on CNA Rules 4.2.0 for two weeks.
Secretariat

CVE/CWE Bundling
The Secretariat summarized a recent discussion with a CNA about grouping 
multiple vulnerabilities into a single CVE Record. While the CNA cited 
increasing vulnerability volumes and operational efficiency as reasons for the 
approach, participants expressed concern that bundling can disrupt security 
tools and processes that rely on vulnerabilities being individually 
identifiable.
Participants generally agreed that the CVE Program should reinforce its 
one-record-per-vulnerability model while carefully considering whether clearer 
requirements are needed. In the near term, the group discussed adding 
contextual information to affected records without discouraging remediation, 
with the proposed approach to be reviewed by the full Board. The Secretariat 
will share options for Board review and CNA engagement.
Longer term, participants supported gathering input from the broader CNA 
community on rising vulnerability volumes, operational challenges, and 
potential Program support, alongside community discussions to identify 
practical solutions.

________________________________
AI Forum Discussion
The Secretariat reported that notes from the recent virtual event on AI’s 
impact on vulnerability management were being finalized. The Secretariat is 
reviewing meeting chat alongside the presentations to capture community 
feedback and plans to conduct a follow-up survey with more targeted questions.
Participants supported expanding the survey beyond event attendees and 
discussed including a carefully framed question on CVE bundling. Participants 
also noted that feedback on broader topics, such as record format and 
governance, could help inform future CVE Program priorities. The TWG will take 
action on post-event messaging.
________________________________
Status Update: RBP and Inactive Policies
The Secretariat reported that the RBP and Inactive policy documents had been 
circulated for approximately three weeks with no additional feedback, and that 
prior redline comments had been addressed. Based on Board precedent, the group 
agreed the policy documents should proceed to formal approval. The policy vote 
will remain open for one week so the documents can be finalized and published 
promptly.
________________________________
Frontier AI Researcher CNA Pilot
Participants noted that the pilot had been reviewed with the Board over several 
meetings and confirmed that it does not change any existing governance 
responsibilities.
Members clarified that the pilot is a limited onboarding and evaluation 
approach for organizations with significant capability and potential scale. It 
does not change the CNA Operational Rules or requirements for existing CNAs, 
but establishes additional expectations for participating organizations. 
Feedback and operational experience will be tracked throughout the pilot via 
the GitHub repository issue tracker to evaluate participants against its 
commitments, identify lessons for future onboarding, and inform whether the 
piloting organizations should continue to hold researcher CNA scope beyond the 
pilot period.
________________________________
CNA Rules 4.2.0
The SPWG reported that the CNA Rules 4.2.0 package is ready for a Board vote. 
Feedback has been offered and incorporated, and supporting documents and issue 
history are available for Board review. The group agreed to use the normal 
two-week voting period for the rules. Because the RBP and Inactive policy votes 
and rules vote will run concurrently on different timelines, the Secretariat 
will clearly distinguish between the votes in Board communications.

This document includes content generated with the assistance of Microsoft Teams 
Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the 
initial draft of the meeting minutes and provide suggestions for summarizing 
key discussion points. All AI-generated content has been reviewed and edited by 
the CVE Program prior to publishing. Please report any inaccuracies or other 
issues to the CVE Program.

Reply via email to