Skip to content

The Coordinated Vulnerability Disclosure (CVD) Program

Cisa September 18, 2026

To report a vulnerability for coordination, use our CVD platform Vulnerability Information and Coordination Environment - New Technology (VINCE-NT), , hosted, and managed by CISA. For more information, see Frequently Asked Questions .

Industrial Control Systems (ICS) Advisories

ICS Advisories provide technical guidance on vulnerabilities impacting industrial control systems and operational technology used in critical infrastructure. Each advisory outlines affected products, explains the potential impacts, and provides recommended mitigation steps. Together, these details help asset owners and operators strengthen resilience against threats targeting their environments. These advisories support informed, proactive risk management for systems essential to public safety, utilities, national security, and a wide range of critical infrastructure sectors.

Common Vulnerabilities and Exposures (CVE) Program

The Common Vulnerabilities and Exposures (CVE) Program provides a globally recognized system for identifying, naming, and cataloging cybersecurity vulnerabilities. Through a distributed network of CVE Numbering Authorities (CNAs), the program ensures that vulnerabilities are documented consistently and publicly, enabling organizations to track, assess, and remediate issues using a shared language. Its transparency and standardization strengthen global vulnerability management and coordination.

Explore featured CISA blog posts that highlight how coordinated vulnerability disclosure strengthens cybersecurity. These posts insights into researcher engagement, responsible reporting, and CISA’s ongoing efforts to modernize vulnerability coordination through platforms like VINCE‑NT.

CISA plays a vital role in safeguarding national and economic security by coordinating the identification, remediation, and disclosure of cybersecurity vulnerabilities that pose risks across critical infrastructure and other essential technologies. This coordination includes vulnerabilities affecting a broad spectrum of technologies such as:

Operational technology (OT) and industrial control systems (ICS),

Internet of things (IoT) devices,

Open source software,

Artificial intelligence (AI),

Through our Coordinated Vulnerability Disclosure (CVD) program, CISA facilitates the timely and synchronized dissemination of vulnerability information and any associated mitigations if available. This process ensures that all relevant stakeholders—including vulnerability reporters, software manufacturers, maintainers, end users/customers, services providers—receive critical information simultaneously, thereby minimizing the window of exploitation and enabling rapid risk mitigation across diverse environments

As an active leader in the CVE Program , CISA's CVD program operationalizes the CISA Top Level Root and the CVE Numbering Authority (CNA) of Last Resort responsibilities by assigning CVE identifiers to vulnerabilities reported to CISA. These functions strengthen the global vulnerability management ecosystem by promoting transparency, fostering trust amongst stakeholders, and supporting a coordinated, systematic response to cybersecurity risks affecting critical infrastructure. For more on CISA's role in the CVE Program, see the CVE program structure .

The Coordinated Vulnerability Disclosure (CVD) Program is a key part of CISA's mission to protect critical infrastructure and bolster national cybersecurity. By identifying, addressing, and publicly disclosing cybersecurity vulnerabilities, the program reduces risks to essential systems. CISA works with stakeholders to quickly actionable mitigation strategies, limiting exploitation opportunities and improving cybersecurity resilience. This collaborative approach builds trust, transparency, and a stronger global cybersecurity ecosystem, ensuring the safety of vital infrastructure.

CISA has broad authority to detect, identify, and receive information "for a cybersecurity purpose security vulnerabilities relating to critical infrastructure in information systems and devices." 6 U.S.C. 659(c)(12). Where a "security vulnerability" means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control. 6 U.S.C 650(25). The Secretary, in coordination with industry and other stakeholders, may develop and adhere to Department policies and procedures for coordinating vulnerability disclosures. 6 U.S.C. 659(n).

An individual (researcher, supplier, etc.) identifies a suspected vulnerability and reports it to CISA through VINCE-NT.

CISA’s Coordinated Vulnerability and Disclosure (CVD) team performs an initial triage to determine if the vulnerability:

CISA’s Coordinated Vulnerability and Disclosure (CVD) team performs an initial triage to determine if the vulnerability Appears legitimate Is actionable Is in scope of CISA’s CVD program Is already known to the vendor or publicly disclosed, including whether it may already have an associated CVE Meets criteria for coordination Outcomes In scope → CV Out of scope → Referred / closed Note: If referred, the report is valid but better handled by another organization or vendor, so CISA directs the reporter to the appropriate channel.

Appears legitimate Is actionable Is in scope of CISA’s CVD program Is already known to the vendor or publicly disclosed, including whether it may already have an associated CVE Meets criteria for coordination

Is in scope of CISA’s CVD program

Is already known to the vendor or publicly disclosed, including whether it may already have an associated CVE

Meets criteria for coordination

Outcomes In scope → CV Out of scope → Referred / closed Note: If referred, the report is valid but better handled by another organization or vendor, so CISA directs the reporter to the appropriate channel.

Out of scope → Referred / closed Note: If referred, the report is valid but better handled by another organization or vendor, so CISA directs the reporter to the appropriate channel.

Note: If referred, the report is valid but better handled by another organization or vendor, so CISA directs the reporter to the appropriate channel.

Once accepted, the case moves into coordinated disclosure where CISA performs: Supplier identification & outreach Technical analysis of vulnerability details and vendor confirmation Timeline tracking Mediation between reporter and vendor when needed Drafting of clear, publication-ready advisory ready language

Supplier identification & outreach

Technical analysis of vulnerability details and vendor confirmation

Mediation between reporter and vendor when needed

Drafting of clear, publication-ready advisory ready language

If the vulnerability appears to meet CVE Program rules , CISA determines whether it should receive a CVE ID and identifies which CVE Numbering Authority (CNA) is responsible for creating and publishing the CVE record. As a CNA, CISA may serve as the authoring CNA when appropriate, ensuring that vulnerabilities reported directly to CISA receive timely, accurate, and standardized CVE documentation

Once a CNA is identified, that CNA will reserve the CVE ID and gather the information necessary for publication as part of the CVE Program process.

CISA and case participants align on: Final advisory text Timeline for publication Coordination with supplier and researcher disclosure plans Cross-stakeholder alignment

Timeline for publication

Coordination with supplier and researcher disclosure plans

Cross-stakeholder alignment

CISA Publishes: CISA Advisory Publish CVE Record enriched content CSAF

Publish CVE Record enriched content

Reporters and Vendors are notified of publication

The process continues with the Known Exploited Vulnerabilities (KEV) Evaluation. For more information, please visit our VINCE-NT GitHub .

CISA discloses vulnerabilities through multiple channels to ensure that users receive complete, accurate, and timely information vulnerabilities and mitigations. Disclosure may include publishing a CVE Record, a comprehensive vulnerability advisory, and/or associated public messaging.

The timeline for disclosure may depend on factors including:

Disclosure Status. Whether the vulnerability has been publicly disclosed or is actively exploited.

Potential Impact. The potential impact on critical infrastructure, national security, or public health.

Vendor Responsiveness. In cases where a vendor is unresponsive or will not establish a reasonable timeframe for remediation, CISA may disclose vulnerabilities as early as 45 days after the initial attempt to the vendor is made, regardless of the availability of a patch or update.

Mitigation Availability and Timeline. The timeline depends on whether mitigations are available and, if not, how long the vendor needs to create mitigations.

Although CISA participates in the interagency Vulnerabilities Equities Process (VEP), vulnerabilities reported to CISA through the CVD process are no subject to VEP adjudication, per Section 5.4 of the VEP Charter. Lean more VEP.

The Vulnerability Disclosure Process (VDP) is separate from CVD. While CVD focuses on coordinating vulnerabilities between researchers and suppliers—including triage, CVE assignment, remediation, and public advisory publication—VDP is the policy and intake process for reporting issues in an organization’s own assets.

VDP provides a clear, authorized way for security researchers and the public to report vulnerabilities they discover in an organization’s public facing systems. A VDP does not involve coordination, remediation, or advisory publication—instead, it simply establishes how an organization receives reports, what is in scope, and what reporters can expect.

The SEI CERT Coordination Center’s CERT Guide to Coordinate Vulnerability Disclosure

This documentation is intended to serve as a guide to those who want to initiate, develop, or improve their own CVD capability.

CISA’s Known Exploited Vulnerabilities (KEV) Catalog

CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.

CISA’s OASIS Common Security Advisory Framework (CSAF) Repository on GitHub

The purpose of this repository is to provide machine-readable security advisories using the OASIS Common Security Advisory Framework (CSAF) Version 2.0 standard for CISA's Information Technology (IT) and Operational Technology (OT) advisories.

OMB Memorandum: Improving Vulnerability Identification, Management, and Remediation

This memorandum provides Federal agencies with guidance for obtaining and managing their vulnerability research programs. Implementation will allow for the security research community ("reporters") to report vulnerability information.

Recommendations for Federal Vulnerability Disclosure Guidelines

This document recommends guidance for establishing a federal vulnerability disclosure framework, properly handling vulnerability reports, and communicating the mitigation and/or remediation of vulnerabilities.

Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

This joint guidance assists software manufacturers and online service providers in creating a framework for collaborating with external security researchers to proactively identify and address vulnerabilities in their products.

[email protected] , 1-844-Say-CISA, [email protected]

Extracted Entities