CISA ties AI-scale vuln discovery to CVE program overhaul
Gold Eagle clearinghouse can ingest hundreds of AI-generated reports, but without new deduplication and data standards the CVE pipeline can't absorb them, and CISA is building both tracks simultaneously.
TL;DR
CISA acting cyber chief Chris Butera laid out a two-track vulnerability management overhaul at a Federal News Network event: Gold Eagle, the Treasury-led AI clearinghouse that ingests and deduplicates AI-discovered vulnerability reports at scale, and concurrent reforms to CVE program governance, data standards, and infrastructure. Butera framed them as connected, the CVE pipeline can't handle the volume AI models are now producing without machine-readable submission formats, deduplication, and a new prioritization mechanism to protect under-resourced open-source maintainers from alert floods.
CISA acting cyber chief Chris Butera used an October 1 Federal News Network fireside chat to publicly connect two vulnerability management efforts that the agency had previously discussed in separate lanes: the Gold Eagle AI clearinghouse and the Common Vulnerabilities and Exposures program reform. The connection matters because it's the first time CISA has framed AI-driven vulnerability discovery at scale as a forcing function for foundational CVE infrastructure changes, rather than treating them as parallel initiatives.
Gold Eagle, launched July 14 under Executive Order 14409 (signed June 2), lets organizations using advanced AI models to find vulnerabilities submit reports in machine-readable formats. "When people are using advanced AI models and finding tens, or sometimes hundreds of vulnerabilities, we are creating machine-readable formats for them to submit those vulnerability reports to us, receiving those at scale and then adding prioritization on the back end," Butera said. Reports that meet coordinated vulnerability disclosure requirements initiate cases in CISA's VINCE platform, which remains the agency's primary CVD tool.
The deduplication function is the operational hinge. "What's important is that we are not sending hundreds of vulnerabilities that are duplicative of each other to open-source software maintainers who are already under-resourced," Butera said. CISA is developing a prioritization mechanism within Gold Eagle to surface "the most critical vulnerabilities" for software producers, a recognition that volume without triage makes the ecosystem worse, not better.
The CVE quality era
Butera also pointed to CISA's September 23 white paper on CVE program reform, describing a shift from what he called the "growth era" to the "quality era." The agency funds the CVE program, which MITRE operates, and is now pushing on "data standards, the data schemas and the technology that is backing the infrastructure." Vulnerability submissions to the program, Butera said, "continue to exceed far what we have seen before."
The reform targets software manufacturers directly. "We want to make sure that our software manufacturers continue to be good stewards and transparent about vulnerability records, so that our defenders can have the information that they need to defend their systems," Butera said. The through-line from Gold Eagle to CVE reforms is the data pipeline: AI-generated reports arriving in volume need machine-readable schemas to be triaged, deduplicated, and prioritized before they ever reach a maintainer or a CVE record.
What's not yet answered
CISA hasn't specified the data standards or schemas it will require for CVE submissions, nor has it indicated when any new requirements would be enforced against vendors or contractors. Butera also declined to commit to a date for finalizing the CIRCIA mandatory incident reporting rule, which the 2026 unified regulatory agenda had slated for September. "I'm not going to give you a date, but I can tell you we are working tirelessly around the clock to finalize the rulemaking," he said. On the infrastructure side, he said CISA is upgrading "reporting infrastructure and reporting forms" and expects to share more "in the coming months."
For defense contractors and any organization that relies on CVE data for patch prioritization, the signal is that CISA's infrastructure plays are moving on two timelines, Gold Eagle is live and accepting participants, while the CVE reforms and reporting-rule upgrades remain in development. The gap between accepting AI-scale submissions and having the governance to handle them is, for now, the story.
Published ·Deep Fathom