Skip to content
Skip to content
June 26, 2026
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy

Microsoft News Now

The Home of Microsoft News Today

Primary Menu
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Light/Dark Button
Subscribe

Home - News - MITRE’s CVE Program Almost Loses Critical Funding Support, Secures Last-Minute Reprieve from CISA for 2025

  • News

MITRE’s CVE Program Almost Loses Critical Funding Support, Secures Last-Minute Reprieve from CISA for 2025

Dave W. Shanahan 1 year ago (Last updated: 1 year ago) 3 minutes read
MITRE's CVE Program Almost Loses Critical Funding Support, Secures Last-Minute Reprieve from CISA for 2025
The Common Vulnerabilities and Exposures (CVE) program, managed by the nonprofit MITRE Corporation, is the global standard for identifying, cataloging, and tracking software vulnerabilities. Since its launch in 1999, the MITRE’s CVE program database has cataloged over 274,000 security flaws, serving as a vital resource for cybersecurity professionals, software vendors, and incident response teams worldwide.

 

The CVE system provides unique identifiers (CVE IDs) for publicly disclosed vulnerabilities, ensuring a common language for reporting and addressing security flaws. This standardization underpins countless cybersecurity tools, national vulnerability databases, and critical infrastructure protections, including those relied upon by Microsoft and other major technology vendors.

Looming Shutdown: Funding Crisis Hits CVE

MITRE's CVE Program Almost Loses Critical Funding Support, Secures Last-Minute Reprieve from CISA for 2025

On April 16, 2025, MITRE announced that its contract with the US Department of Homeland Security (DHS) to operate and modernize the CVE program was set to expire, with no immediate renewal in sight. An internal memo from MITRE’s Vice President Yosry Barsoum warned that a break in service would have severe consequences:

“If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of critical infrastructure.”

The news sent shockwaves through the cybersecurity community. Experts highlighted that a lapse in CVE services would disrupt vulnerability tracking, slow down security advisories, and jeopardize incident response efforts across the globe. The potential shutdown risked fragmenting the vulnerability ecosystem, undermining trust, and leaving organizations exposed to emerging threats.

Community and Industry Response

The abrupt funding crisis prompted urgent calls for action from lawmakers, cybersecurity leaders, and industry groups. House Science Committee Ranking Member Zoe Lofgren and Homeland Security Ranking Member Bennie Thompson labeled the funding lapse “reckless and ignorant,” warning that it would undermine global cybersecurity.

Meanwhile, the CVE Board announced the formation of the CVE Foundation, a new nonprofit organization designed to ensure the program’s independence and sustainability. The foundation aims to eliminate the risk of a single point of failure and maintain the CVE program as a globally trusted, community-driven initiative.

Last-Minute Reprieve: CISA Steps In

MITRE's CVE Program Almost Loses Critical Funding Support, Secures Last-Minute Reprieve from CISA for 2025

In response to mounting concerns, the US Cybersecurity and Infrastructure Security Agency (CISA) executed an emergency extension of MITRE’s contract just hours before the funding was set to lapse. CISA emphasized the program’s critical importance (via Forbes):

“The CVE Program is invaluable to the cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services.”

This extension, however, is temporary—lasting just 11 months—leaving the long-term future of the CVE program uncertain. The situation has underscored the need for a more sustainable, multi-stakeholder approach to funding and governance.

What’s Next for the MITRE’s CVE Program?

While the immediate crisis has been averted, questions remain about the program’s long-term stability. The creation of the CVE Foundation signals a shift toward greater independence and global collaboration, but the transition will require careful planning and industry support.

For now, MITRE continues to operate the CVE program, and the cybersecurity community can rely on the continuity of vulnerability tracking and advisories. However, the episode serves as a stark reminder of the fragility of critical cybersecurity infrastructure and the need for resilient, community-driven solutions.

MITRE’s CVE program narrowly avoided a shutdown that could have rippled across the global cybersecurity landscape. While CISA’s last-minute funding extension ensures continuity for now, the future of vulnerability management depends on sustainable funding, transparent governance, and international cooperation. Organizations, vendors, and governments must remain vigilant and proactive to safeguard the world’s digital infrastructure.

About The Author

MITRE's CVE Program

Dave W. Shanahan

I’m Dave W. Shanahan, a Microsoft enthusiast with a passion for Windows, Xbox, Microsoft 365 Copilot, Azure, and more. I started MSFTNewsNow.com to keep the world updated on Microsoft news. Based in Massachusetts, you can email me at davewshanahan@gmail.com.

See author's posts

Like this:

LikeLoading…

Related


Discover more from Microsoft News Now

Subscribe to get the latest posts sent to your email.

Tags: AzureCybersecurityGitHubMicrosoftOutlookSecuritySurfaceTwitterWindows

Post navigation

Previous: Xbox Game Pass April 2025 Wave 2 Update: GTA V Returns Today, Modern Warfare II and Clair Obscur: Expedition 33 Headline an Impressive Lineup
Next: Xbox April 2025 Update brings exciting new features: Buy Games on Mobile, Stream Your Own Games on Console, and Much More

Related Stories

XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News
  • XBOX and Gaming

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 14 hours ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News
  • XBOX and Gaming

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 15 hours ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 3 days ago 0

AccessibilityAmazonAndroidAuthenticationAzureCall of DutyCopilotCybersecurityDeveloperEnterpriseFree Play DaysGamingGenerative AIGitHubGoogleLinkedinMicrosoftMicrosoft 365Microsoft 365 CopilotMicrosoft CopilotMicrosoft EdgeMicrosoft StoreMicrosoft TeamsNext Week on XBOXOpenAIOutlookPatch TuesdayPrivacySecuritySettingsSharePointSurfaceTwitterWindowsWindows 10Windows 11Windows InsiderXBOXXBOX Game PassXBOX Game Pass UltimateXBOX OneXBOX Play AnywhereXBOX Series XXBOX Series X|SXBOX Wire

Useful Links

  • AI and Copilot (249)
  • Azure & Cloud (35)
  • Developers (3)
  • Enterprise (3)
  • How To Guides (98)
  • Microsoft 365/Office (95)
  • Microsoft Announcements (97)
  • News (1,264)
  • Security (78)
  • Surface (47)
  • Windows (166)
  • XBOX and Gaming (414)

You May Have Missed

XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News
  • XBOX and Gaming

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 14 hours ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News
  • XBOX and Gaming

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 15 hours ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 3 days ago 0
Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence
  • News
  • XBOX and Gaming

Super XBOX News Roundup for June 23, 2026: Age of Empires: Mobile PC Edition Launch, Game Pass Updates, and Xbox Reset Turbulence

Dave W. Shanahan 3 days ago 0
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Copyright © 2026 All rights reserved. ReviewNews by AF themes.

    %d