cisatrade-pressNewsThe Broadside2 min read

AI vulnerability surge strains CVE and KEV programs

A record every seven minutes turns vulnerability disclosure from a cataloging problem into a triage failure for downstream patch teams.


TL;DR

Inside Cybersecurity reports that Common Vulnerabilities and Exposures (CVE) Board and CVE Consumer Working Group members used a July 1 Institute for Security and Technology webinar to warn that the Cybersecurity and Infrastructure Security Agency (CISA)-funded CVE program cannot scale on current process. Jay Jacobs said CVE is publishing about one record every seven minutes, and Tod Beardsley said CISA’s Known Exploited Vulnerabilities (KEV) catalog is similarly exposed. Jen Ellis flagged vendor pressure to bundle multiple flaws under one identifier, which would land hardest on patch teams.

Inside Cybersecurity’s account of the July 1 Institute for Security and Technology webinar is a pressure test for vulnerability infrastructure security teams already treat as plumbing. The report tied the debate to Anthropic’s April 7 Claude Mythos Preview and June 9 Fable 5 releases, frontier models described as having advanced cyber discovery capabilities. The question is whether the federal cataloging machinery can survive discovery at machine speed.

The Common Vulnerabilities and Exposures (CVE) program, funded by the Cybersecurity and Infrastructure Security Agency (CISA) and run by MITRE, was described by runZero’s Tod Beardsley as at risk of being “over” if it keeps operating as it does now. Jay Jacobs of Empirical Security said CVE is publishing about one record every seven minutes and called the rate unsustainable for a system built by humans for humans. Beardsley said CISA’s Known Exploited Vulnerabilities (KEV) catalog would face the same problem without a larger response, while noting CISA’s June 10 Binding Operational Directive is moving KEV toward risk-based patch prioritization.

The Cisco fight is the useful concrete example. Jen Ellis highlighted Cisco’s June 2 plan to assign one CVE identifier to multiple vulnerabilities to handle volume. Jacobs summarized the vendor rationale as a claim that individual tracking is too hard, then said grouping would kill consumers’ ability to manage, track and prioritize vulnerability data. The CVE program answered on June 16 that it would not support grouping multiple vulnerabilities under a single CVE identifier.

No one on the webinar changed a federal deadline. The Monday problem is tool and process hygiene: assume higher record volume, test whether scanners, ticketing rules and risk scoring break when vendors compress vulnerability detail, and treat any grouped identifier as missing evidence in the queue. The shortcut may save the record producer time. It makes the defender reconstruct the missing context later.


Published ·Deep Fathom