By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: MITRE warns over lapse in CVE coverage | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > MITRE warns over lapse in CVE coverage | Computer Weekly
News

MITRE warns over lapse in CVE coverage | Computer Weekly

News Room
Last updated: 2025/04/15 at 6:05 PM
News Room Published 15 April 2025
Share
SHARE

One of the cyber security world’s most significant assets, the common vulnerabilities and exposures (CVE) system operated by US-based non-profit MITRE appears to be heading for trouble after it emerged that the contract pathway for MITRE to continue to run the project on behalf of the US authorities, is set to lapse on Wednesday 16 April with no replacement ready.

In a letter to MITRE board members circulated today, a copy of which has been reviewed by Computer Weekly, Yosry Barsoum, vice president and director at the Centre for Securing Homeland (CSH) at MITRE, said the US government was currently making “considerable efforts” to continue MITRE’s longstanding role in the CVE programme.

“If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of critical infrastructure,” wrote Barsoum.

“MITRE continues to be committed to CVE as a global resource. We thank you as a member of the CVE Board for your continued partnership,” he added.

A spokesperson for MITRE confirmed the legitimacy of Barsoum’s statement to Computer Weekly. They described the CVE programme as a “foundational pillar” of the cyber sector, anchoring a global industry worth close to $40bn (£30bn).

The 25 year-old CVE system is designed to serve as a reference and repository for disclosed cyber security vulnerabilities, and has been maintained by MITRE since its inception at the end of the 1990s, with funding drawn from the National Cyber Security Division of the Department of Homeland Security.

Over the years its impact on the world of security research has been of immense significance, providing cyber defenders with data on emerging vulnerabilities and threats, some of which have been implicated in some of the largest cyber incidents ever seen – such as WannaCry, SolarWinds Sunburst, Log4j, and MOVEit to name but a few.

Its continuing work will be familiar to most thanks to the sheer volume of CVEs – recognisable by their unique identifiers comprising the letters CVE, the year, and a numeric code – released on the second Tuesday of every month by Microsoft in its Patch Tuesday update.

If it was to have to cease operations, even temporarily pending a contract renewal, the impact would be keenly felt across the entire technology industry. Patch Tuesday aside, the current number of CVEs of all types being discovered and disclosed is running at record highs and shows no signs of slowing.

Disruption to the CVE system would be a gift to both financially-motivated cyber criminals and nation-state actors alike, who would be able to swiftly take advantage of any downtime as they continue to seek out, develop and weaponise new vulnerabilities, while security professionals would be left fumbling in the dark.

Coming amidst deep and painful government cuts being made in the US, the potential risk to the national security postures of the US and its allies from states such as China and Russia, is also extremely serious – a fact not lost on many members of the security community who took to social media late 15 April to spread the word.

Writing on LinkedIn, one observer speculated that the deprecation of MITRE’s contract was by design, and that taken alongside cuts to the likes of the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST), the US was tearing down core security institutions amid a significant ongoing cyber crisis.

Filling the gap

But with customary community spirit, many cyber professionals are already stepping up to address the looming shutdown. Patrick Garrity, a security researcher at VulnCheck, said: “We want to take a moment to thank MITRE for its decades of contributions to the CVE programme.

“Given the current uncertainty surrounding which services at MITRE or within the CVE programme may be affected, VulnCheck has proactively reserved 1,000 CVEs for 2025.”

Garrity added that VulnCheck’s reporting service would continue to assign CVE numbers for as long as it could do so.

“VulnCheck is closely monitoring the situation to ensure that both the community and our customers continue to receive timely, accurate vulnerability data,” he said.

MITRE added that historical CVE Records will continue to be available at GitHub.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article 10 Best Dropbox Paper Alternatives and Competitors 2025
Next Article OpenAI may be building a social network for some reason
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Microsoft 365’s Family plan is nearly 50% off on Amazon
Gadget
Student Loan Borrowers, You Have Until Summer to Prevent Your Wages From Being Garnished
News
What the Investments and Securities Act means for Nigeria’s crypto
Computing
UK tech funding roundup: This week’s deals from Juice to Zeus – UKTN
News

You Might also Like

News

Student Loan Borrowers, You Have Until Summer to Prevent Your Wages From Being Garnished

6 Min Read
News

UK tech funding roundup: This week’s deals from Juice to Zeus – UKTN

1 Min Read
News

Google I/O 2025: What to Expect and How to Watch

9 Min Read
News

Broadcom letters demonstrate push to VMware subscriptions | Computer Weekly

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?