CVE Board Meeting Minutes August 19, 2026 (9:00 a.m. – 11:00 a.m. EDT) CVE Board Attendance ☒ Pete Allor ☐ Ken Armstrong, EWA – Canada, an Intertek Company<https://urldefense.us/v2/url?u=https-3A__www.intertek.com_cybersecurity_ewa-2Dcanada_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=IznsD8i8uMnvlKaNUVPzek79q2ijp89qJj-pJh7OylE&e=> ☒ Tod Beardsley, Austin Hackers Anonymous<https://urldefense.us/v2/url?u=https-3A__takeonme.org_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=jyTWp9OSkK1AC64PaGTSUldDsTHiIVlTcFqUKRSToEA&e=> (AHA!) ☒ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency (CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=tOfkvjiO3d2-qCrcOYdEpCnOufk26wGV0vHJTAH04dk&e=> ☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/> ☒ William Cox, Black Duck Software, Inc.<https://urldefense.us/v2/url?u=https-3A__www.blackduck.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=1DnGgciabdsUkyKZeW4UkYNP4XVOnBTFaQJ7z_2pcC4&e=> ☒ Jen Ellis, NextJen Security<https://urldefense.us/v2/url?u=https-3A__uk.linkedin.com_in_infosecjen&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=yAAyrsLVTBsrj6mn4XrypMeOiJuxjnXxTvweEQS9BNM&e=> ☒ Madison Ficorilli, GitHub Security Lab<https://urldefense.us/v2/url?u=https-3A__securitylab.github.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=6us6EBYJjz1QwUMHlo5hlS5vCVaC-rRrVZFvz8hz2cU&e=> ☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency (CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=tOfkvjiO3d2-qCrcOYdEpCnOufk26wGV0vHJTAH04dk&e=> ☐ Tim Keanini ☐ Kent Landfield ☒ Scott Lawler, LP3<https://urldefense.us/v2/url?u=https-3A__lp3.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=ZnuZHpvrp0th-6FFmJXA29Rz9cy4L3bHiwXkrQvrdUg&e=> ☐ Art Manion ☒ MegaZone (CNA Board Liaison), F5, Inc.<https://urldefense.us/v2/url?u=https-3A__www.f5.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=2bXKHGkCer3bXdfH55A8pQ0MOTDdoN6wWfL8pccqx7w&e=> ☐ Tom Millar, Cybersecurity and Infrastructure Security Agency (CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=tOfkvjiO3d2-qCrcOYdEpCnOufk26wGV0vHJTAH04dk&e=> ☒ Yogesh Mittal, Red Hat, Inc.<https://urldefense.us/v2/url?u=https-3A__www.redhat.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=7Uu7AwtAqbZTXNPtSvS-HMNFxCmJRNv_vRo5scRxBk8&e=> ☒ Chandan Nandakumaraiah ☐ Kathleen Noble ☒ Lisa Olson, Microsoft<https://urldefense.us/v2/url?u=https-3A__www.microsoft.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=Jvvyc-wP9qrUi1LAgivsxo7FW6LwClfSHE7mabOz4hw&e=> ☒ Carloine D. Rosin, NIST<https://urldefense.us/v2/url?u=https-3A__www.nist.gov_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=De5AxedigSCZlX1sCFWlMo4i6kFPjSUMCTTGHteYGDg&e=> ☐ Shannon Sabens, CrowdStrike, Inc.<https://urldefense.us/v2/url?u=https-3A__www.crowdstrike.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=ostXGVq8CjYczaCS7i7Z6X_dxmlKfT8DerchY2mfEt8&e=> ☐ Takayuki Uchiyama, Panasonic Holdings Corporation<https://urldefense.us/v2/url?u=https-3A__holdings.panasonic_global_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=YH9u9b1cTHrfAjr0qqWDfcvvXh3sMph6Ujmfoqt2vUA&e=> ☐ David Waltermire ☒ James “Ken” Williams, Broadcom Inc.<https://urldefense.us/v2/url?u=https-3A__www.broadcom.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=o8Mw-_U-RfSkieqLOqlvKiOrpUnBidVH2v_jBt7UooQ&e=>
MITRE CVE Team Attendance ☒ Kris Britton ☒ Christine Deal ☐ Bob Roberge ☒ Anthony Singleton ☒ Jo Bazar ☒ Alec J Summers Agenda 1. Frontier AI Researcher CNA Pilot 2. Fall Technical Workshop: October 29 (tentative) 3. Open Discussion New Action Items from Today’s Meeting New Action Item Responsible Party Engage relevant working groups to explain and further socialize the Frontier AI Researcher CNA Pilot and address questions about its purpose, scope, and operating model. Board/Secretariat Convene a small follow-up group to review CNA scope, duplicate handling, credit, and related concerns raised in connection with AI-enabled vulnerability discovery and return with recommended adjustments or confirmation that no changes are needed. Board/Secretariat Conduct outreach to potential CNA Technical Workshop speakers, including practitioners who are not typically present, to broaden participation and perspectives. Board Communicate recently approved policy changes to the CNA community through established email/newsletter channels before the Fall Technical Workshop. Secretariat Add clarification to the inactive CNA policy, explaining the disposition of unused reserved CVE IDs when a CNA is decertified. Secretariat 1. Frontier AI Researcher CNA Pilot The Board discussed the Frontier AI Researcher CNA Pilot, including community perceptions of its purpose, terminology, and relationship to the existing CNA framework. The Board reaffirmed that the pilot operates within existing CNA rules and scopes and discussed the importance of clear communication and community engagement. The Board also considered broader implications of AI-assisted vulnerability discovery, including scope, duplicate findings, disclosure, and credit. Relevant working groups will be engaged to help clarify these issues and inform future discussions. ________________________________ 2. Fall Technical Workshop The Board reviewed planning for the CNA Fall Technical Workshop, including potential agenda topics, format, and timing. The workshop is expected to include Program updates, policy discussions, and opportunities for community input and discussion. The Board emphasized the importance of practitioner and CNA participation and encouraged outreach to a broad range of potential speakers. Planning will continue, with the workshop tentatively targeted for late October. ________________________________ 3. Open Discussion Inactive CNA Policy Clarification The Board discussed a clarification to the recently approved inactive CNA policy concerning blocks of CVE IDs that have been reserved but remain unused when a CNA is decertified. The existing operational practice is for unused IDs to be returned and rejected as unused for the applicable calendar year. Participants agreed that the policy should contain a brief statement documenting that practice. The clarification was considered non-material because it documents an existing process rather than establishing a new policy requirement. No objection was raised to adding the clarification, and the Board agreed that another vote is not required. This document includes content generated with the assistance of Microsoft Teams Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the initial draft of the meeting minutes and provide suggestions for summarizing key discussion points. All AI-generated content has been reviewed and edited by the CVE Program prior to publishing. Please report any inaccuracies or other issues to the CVE Program.
