Skip to main content
Back to Blog
16 April 2025, byZebrabyte Breaches and incidents

MITRE and CVE Program – What Happens After the Agreement Expired on 16 April 2025?

MITRE and CVE Program – What Happens After the Agreement Expired on 16 April 2025?

The Common Vulnerabilities and Exposures (CVE®) program is one of the fundamental pillars of global cybersecurity.

What is CVE and why is it so important in cybersecurity?

Programul Common Vulnerabilities and Exposures (CVE®) It is one of the fundamental pillars of global cybersecurity. CVE provides a standardized system for identifying and cataloguing vulnerabilities found in IT software, services and infrastructures. Without it, solutions such as SIEM, EDR, patch management or threat intelligence would work... on the go.

What happened now?

On April 15, 2015, it was Internal document signed by Yosry BarsoumThe Vice-President, who confirmed that MITRE contract for CVE development and maintenance officially expires on 16 April 2025The official confirmation also came from MITRE, in a response to Cyber Security News.

This contract also includes other essential components such as:

  • CWE – Common Weakness Enumeration

  • Support for the modernization of the reporting infrastructure

  • Updating the database to JSON format

  • Extinderea spre Service Vulnerabilities, nu doar software clasic

What does this mean for the industry?

If the contract is not extended, consequences may arise. grave:

  1. Slowing down CVE registration This leads to delayed security patches.

  2. Impact asupra vendorilor which rely on CVEs to prioritize and automate response processes.

  3. Risks to critical infrastructures which is based on these data for active protection.

  4. Threat Intelligence, SIEM and EDRwhich consumes the CVE data.

Ce spune MITRE?

“The government continues to make considerable efforts to support the role of MITRE in the program. MITRE remains dedicated to CVE as a global resource.”

In other words, it is possible that the work will continue in the near future, but Without a guaranteed funding, everything is uncertain.

Why is this change worrying?

Programul CVE este the cornerstone for an industry estimated at more than $37 billionAny interruption can cause:

  • Confusion among suppliers

  • Lack of confidence in the timeliness of vulnerabilities

  • An opportunity for malicious actors to exploit the chaos window

What is next?

It remains to be seen if:

  • US government to extend contract with MITRE

  • There will appear a nou operator pentru programul CVE

  • The open-source community will have to fill the gap

Concluzie

We are at a critical time for global cybersecurity. CVE is more than just a database – it’s sistemul imunitar al internetului modernKeep an eye on the developments over the next few days.

What can you do as a security professional?

  • Be careful with new CVEs, even if there are delays.

  • Use alternative sources such as ExploitDB, NVD, regional CERTs

  • Prepare your infrastructure for possible delays in automatic updates


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert