Skip to content
CISA Upgrades Vulnerability Reporting Platform with More Automation

CISA Upgrades Vulnerability Reporting Platform with More Automation

Infosecurity-Magazine September 18, 2026

The US Cybersecurity and Infrastructure Security Agency (CISA) has upgraded its vulnerability reporting and coordination platform to allow for more automation and streamlined processes, as well as new built-in tools that vulnerability researchers can use.

Since 2020, CISA has been using Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed that same year by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI).

From September 17, 2026, the US cybersecurity agency is now using VINCE – New Technology (VINCE-NT).

VINCE-NT is a modernized, CISA-managed platform for vulnerability reporting and coordination. It improves how vulnerability reporters, product suppliers and CISA case managers collaborate throughout the disclosure process,” CISA said in an announcement published on social media on September 17.

The agency also said the change shifts ownership, sponsorship and management of the platform to its Coordinated Vulnerability Disclosure (CVD) team and enables improved integration with its internal tools and processes.

Enhancements include:

A user-friendly interface that makes submitting vulnerability reports easier, safer and reduces friction

Enhanced triage effectiveness enabling teams to better prioritize the most critical vulnerabilities

Simplified advisory publication workflows through automation

Built-in tools enabling transparent collaboration among all parties while protecting sensitive data

Enhanced reporting case metrics, giving CISA’s CVD team actionable insights to improve coordination

Stronger support for multi-party coordination and developing advisories

Additionally, VINCE-NT revamped some of the vulnerability terminology used by CISA until now. The “vendors/developer/maintainer” entry becomes “supplier,” “product” is replaced by “component” and “researcher/finder” is now “reporter.”

In an FAQ the transition , CISA said active VINCE cases will be transitioned over the coming weeks.

For stakeholders who have active cases on VINCE, a case coordinator will reach out and convey the transition date.

Inactive cases will not be moved to VINCE-NT but will still be available on VINCE. The US agency said organizations should update internal reporting procedures to reflect that vulnerability submissions to CISA should now be made through VINCE-NT.

Read now: Linux Foundation's Akrites to Go Live in September

AI Companies to Play Bigger Role in CVE Program, Says CISA News 15 April 2026

AI Companies to Play Bigger Role in CVE Program, Says CISA

NIST Seeks Public Input on AI-Ready NVD Modernization News 12 August 2026

NIST Seeks Public Input on AI-Ready NVD Modernization

CISA Throws Lifeline to CVE Program with Last-Minute Contract Extension News 17 April 2025

CISA Throws Lifeline to CVE Program with Last-Minute Contract Extension

CVE Program Launches Two New Forums to Enhance CVE Utilization News 3 July 2025

CVE Program Launches Two New Forums to Enhance CVE Utilization

European Cybersecurity Agency ENISA Seeks Top-Tier Status in CVE Program News 15 April 2026

European Cybersecurity Agency ENISA Seeks Top-Tier Status in CVE Program

What’s Hot on Infosecurity Magazine?

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

AI Agent Carries Out Multi-Stage Data Theft Attack

Most Firms Unable to Recover Quickly from Ransomware

Cisco Warns of Active Exploitation of Critical ISE Flaw

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

Anthropic Reveals Yet Another Cybersecurity Incident

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How to Manage Enterprise Cyber Resilience in the Age of AI

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Platforms (1)