CVE Board Meeting Minutes
August 19, 2026 (9:00 a.m. – 11:00 a.m. EDT)

CVE Board Attendance
☒ Pete Allor
☐ Ken Armstrong, EWA – Canada, an Intertek 
Company<https://urldefense.us/v2/url?u=https-3A__www.intertek.com_cybersecurity_ewa-2Dcanada_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=IznsD8i8uMnvlKaNUVPzek79q2ijp89qJj-pJh7OylE&e=>
☒ Tod Beardsley, Austin Hackers 
Anonymous<https://urldefense.us/v2/url?u=https-3A__takeonme.org_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=jyTWp9OSkK1AC64PaGTSUldDsTHiIVlTcFqUKRSToEA&e=>
 (AHA!)
☒ Lindsey Cerkovnik, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=tOfkvjiO3d2-qCrcOYdEpCnOufk26wGV0vHJTAH04dk&e=>
☒ Chris Coffin (MITRE At Large), The MITRE Corporation<https://www.mitre.org/>
☒ William Cox, Black Duck Software, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.blackduck.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=1DnGgciabdsUkyKZeW4UkYNP4XVOnBTFaQJ7z_2pcC4&e=>
☒ Jen Ellis, NextJen 
Security<https://urldefense.us/v2/url?u=https-3A__uk.linkedin.com_in_infosecjen&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=yAAyrsLVTBsrj6mn4XrypMeOiJuxjnXxTvweEQS9BNM&e=>
☒ Madison Ficorilli, GitHub Security 
Lab<https://urldefense.us/v2/url?u=https-3A__securitylab.github.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=6us6EBYJjz1QwUMHlo5hlS5vCVaC-rRrVZFvz8hz2cU&e=>
☐ Jay Gazlay, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=tOfkvjiO3d2-qCrcOYdEpCnOufk26wGV0vHJTAH04dk&e=>
☐ Tim Keanini
☐ Kent Landfield
☒ Scott Lawler, 
LP3<https://urldefense.us/v2/url?u=https-3A__lp3.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=ZnuZHpvrp0th-6FFmJXA29Rz9cy4L3bHiwXkrQvrdUg&e=>
☐ Art Manion
☒ MegaZone (CNA Board Liaison), F5, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.f5.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=2bXKHGkCer3bXdfH55A8pQ0MOTDdoN6wWfL8pccqx7w&e=>
☐ Tom Millar, Cybersecurity and Infrastructure Security Agency 
(CISA)<https://urldefense.us/v2/url?u=https-3A__www.dhs.gov_cisa_cybersecurity-2Ddivision_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=tOfkvjiO3d2-qCrcOYdEpCnOufk26wGV0vHJTAH04dk&e=>
☒ Yogesh Mittal, Red Hat, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.redhat.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=7Uu7AwtAqbZTXNPtSvS-HMNFxCmJRNv_vRo5scRxBk8&e=>
☒ Chandan Nandakumaraiah
☐ Kathleen Noble
☒ Lisa Olson, 
Microsoft<https://urldefense.us/v2/url?u=https-3A__www.microsoft.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=Jvvyc-wP9qrUi1LAgivsxo7FW6LwClfSHE7mabOz4hw&e=>
☒ Carloine D. Rosin, 
NIST<https://urldefense.us/v2/url?u=https-3A__www.nist.gov_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=De5AxedigSCZlX1sCFWlMo4i6kFPjSUMCTTGHteYGDg&e=>
☐ Shannon Sabens, CrowdStrike, 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.crowdstrike.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=ostXGVq8CjYczaCS7i7Z6X_dxmlKfT8DerchY2mfEt8&e=>
☐ Takayuki Uchiyama, Panasonic Holdings 
Corporation<https://urldefense.us/v2/url?u=https-3A__holdings.panasonic_global_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=YH9u9b1cTHrfAjr0qqWDfcvvXh3sMph6Ujmfoqt2vUA&e=>
☐ David Waltermire
☒ James “Ken” Williams, Broadcom 
Inc.<https://urldefense.us/v2/url?u=https-3A__www.broadcom.com_&d=DwMGaQ&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=GU_sstYAPV42FoHir4NMu-pDhUFVO4X2GpC0s-b0KgE&m=25hrDt4NwbNmDZWDT0T-cWPJWJGIj70xXcdMii3JV0pEYlvQ_XUHyLHEQ-Wffe91&s=o8Mw-_U-RfSkieqLOqlvKiOrpUnBidVH2v_jBt7UooQ&e=>


MITRE CVE Team Attendance
☒ Kris Britton
☒ Christine Deal
☐ Bob Roberge
☒ Anthony Singleton
☒ Jo Bazar
☒ Alec J Summers

Agenda
1. Frontier AI Researcher CNA Pilot
2. Fall Technical Workshop: October 29 (tentative)
3. Open Discussion
New Action Items from Today’s Meeting
New Action Item

Responsible Party

Engage relevant working groups to explain and further socialize the Frontier AI 
Researcher CNA Pilot and address questions about its purpose, scope, and 
operating model.
Board/Secretariat
Convene a small follow-up group to review CNA scope, duplicate handling, 
credit, and related concerns raised in connection with AI-enabled vulnerability 
discovery and return with recommended adjustments or confirmation that no 
changes are needed.
Board/Secretariat
Conduct outreach to potential CNA Technical Workshop speakers, including 
practitioners who are not typically present, to broaden participation and 
perspectives.
Board
Communicate recently approved policy changes to the CNA community through 
established email/newsletter channels before the Fall Technical Workshop.
Secretariat
Add clarification to the inactive CNA policy, explaining the disposition of 
unused reserved CVE IDs when a CNA is decertified.
Secretariat

1. Frontier AI Researcher CNA Pilot
The Board discussed the Frontier AI Researcher CNA Pilot, including community 
perceptions of its purpose, terminology, and relationship to the existing CNA 
framework. The Board reaffirmed that the pilot operates within existing CNA 
rules and scopes and discussed the importance of clear communication and 
community engagement.
The Board also considered broader implications of AI-assisted vulnerability 
discovery, including scope, duplicate findings, disclosure, and credit. 
Relevant working groups will be engaged to help clarify these issues and inform 
future discussions.
________________________________
2. Fall Technical Workshop
The Board reviewed planning for the CNA Fall Technical Workshop, including 
potential agenda topics, format, and timing. The workshop is expected to 
include Program updates, policy discussions, and opportunities for community 
input and discussion.
The Board emphasized the importance of practitioner and CNA participation and 
encouraged outreach to a broad range of potential speakers. Planning will 
continue, with the workshop tentatively targeted for late October.
________________________________
3. Open Discussion
Inactive CNA Policy Clarification
The Board discussed a clarification to the recently approved inactive CNA 
policy concerning blocks of CVE IDs that have been reserved but remain unused 
when a CNA is decertified. The existing operational practice is for unused IDs 
to be returned and rejected as unused for the applicable calendar year.
Participants agreed that the policy should contain a brief statement 
documenting that practice. The clarification was considered non-material 
because it documents an existing process rather than establishing a new policy 
requirement. No objection was raised to adding the clarification, and the Board 
agreed that another vote is not required.


This document includes content generated with the assistance of Microsoft Teams 
Copilot, a generative AI tool. Microsoft Teams Copilot was used to generate the 
initial draft of the meeting minutes and provide suggestions for summarizing 
key discussion points. All AI-generated content has been reviewed and edited by 
the CVE Program prior to publishing. Please report any inaccuracies or other 
issues to the CVE Program.

Reply via email to