Skip to content
ThreatCluster

CVE Numbering Authority (CNA) Process Enhancements Announced

First seen 16 May 2026, 11:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 17, 2026 at 10:18 UTC
  • CNA program requires organizations to demonstrate expertise in vulnerability management.
  • CNA hierarchy includes Program Root, Root, and Sub-CNAs with defined responsibilities.
  • Vulnerabilities must have accessible URLs for proper vetting and publication.

The CVE Numbering Authority (CNA) program has been detailed, emphasizing the vetting process for software vulnerabilities submitted for CVE IDs. Organizations wishing to become CNAs must demonstrate expertise and follow strict guidelines. The hierarchy of CNAs is established, with Program Root, Root, and Sub-CNAs, each with specific responsibilities. CNAs are required to provide accessible URLs for reported vulnerabilities. This structured approach aims to ensure consistency and reliability in vulnerability reporting and management. The National Vulnerability Database (NVD) will analyze and publish these vulnerabilities after CVE ID assignment. The onboarding process for CNAs includes rigorous training and compliance checks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 127d ago How this analysis works

Timeline

2026-05-16
CNA program details published
NIST outlines the process for organizations to become CNAs and the vetting of vulnerabilities.
nvd.nist.gov
2026-05-16
CVE definition clarified
NIST defines vulnerabilities and their impact on confidentiality, integrity, and availability.
nvd.nist.gov

More articles in this cluster (2)