Back Infosecurity-Magazine CISA Upgrades Vulnerability Reporting Platform with More Automation
The US Cybersecurity and Infrastructure Security Agency (CISA) has upgraded its vulnerability reporting and coordination platform to allow for more automation and streamlined processes, as well as new built-in tools that vulnerability researchers can use.
Since 2020, CISA has been using Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed that same year by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI).
From September 17, 2026, the US cybersecurity agency is now using VINCE – New Technology (VINCE-NT).
“VINCE-NT is a modernized, CISA-managed platform for vulnerability reporting and coordination. It improves how vulnerability reporters, product suppliers and CISA case managers collaborate throughout the disclosure process,” CISA said in an announcement published on social media on September 17.
The agency also said the change shifts ownership, sponsorship and management of the platform to its Coordinated Vulnerability Disclosure (CVD) team and enables improved integration with its internal tools and processes.
Enhancements include:
A user-friendly interface that makes submitting vulnerability reports easier, safer and reduces friction
Enhanced triage effectiveness enabling teams to better prioritize the most critical vulnerabilities
Simplified advisory publication workflows through automation
Built-in tools enabling transparent collaboration among all parties while protecting sensitive data
Enhanced reporting case metrics, giving CISA’s CVD team actionable insights to improve coordination
Stronger support for multi-party coordination and developing advisories
Additionally, VINCE-NT revamped some of the vulnerability terminology used by CISA until now. The “vendors/developer/maintainer” entry becomes “supplier,” “product” is replaced by “component” and “researcher/finder” is now “reporter.”
In an FAQ the transition , CISA said active VINCE cases will be transitioned over the coming weeks.
For stakeholders who have active cases on VINCE, a case coordinator will reach out and convey the transition date.
Inactive cases will not be moved to VINCE-NT but will still be available on VINCE. The US agency said organizations should update internal reporting procedures to reflect that vulnerability submissions to CISA should now be made through VINCE-NT.
Read now: Linux Foundation's Akrites to Go Live in September
AI Companies to Play Bigger Role in CVE Program, Says CISA News 15 April 2026
AI Companies to Play Bigger Role in CVE Program, Says CISA
NIST Seeks Public Input on AI-Ready NVD Modernization News 12 August 2026
NIST Seeks Public Input on AI-Ready NVD Modernization
CISA Throws Lifeline to CVE Program with Last-Minute Contract Extension News 17 April 2025
CISA Throws Lifeline to CVE Program with Last-Minute Contract Extension
CVE Program Launches Two New Forums to Enhance CVE Utilization News 3 July 2025
CVE Program Launches Two New Forums to Enhance CVE Utilization
European Cybersecurity Agency ENISA Seeks Top-Tier Status in CVE Program News 15 April 2026
European Cybersecurity Agency ENISA Seeks Top-Tier Status in CVE Program
What’s Hot on Infosecurity Magazine?
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
Cisco Warns of Active Exploitation of Critical ISE Flaw
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
Anthropic Reveals Yet Another Cybersecurity Incident
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How to Manage Enterprise Cyber Resilience in the Age of AI
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
