Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
SpaceX sets 0 billion valuation, confirms 2026 IPO plans

SpaceX sets $800 billion valuation, confirms 2026 IPO plans

13 December 2025
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Wisconsin couple’s ACA health plan soars from  a month to ,600 as subsidies expire

Wisconsin couple’s ACA health plan soars from $2 a month to $1,600 as subsidies expire

13 December 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » CVE Program Funding Cut—What It Means And What To Do Next
Innovation

CVE Program Funding Cut—What It Means And What To Do Next

Press RoomBy Press Room16 April 20256 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
CVE Program Funding Cut—What It Means And What To Do Next

U.S. President Donald Trump has cut funding for the global database of security flaws, the Common Vulnerabilities and Exposures database from Apr. 16. The not-for-profit organization that runs the database, MITRE, confirmed its contract with the U.S. Department of Homeland Security to operate the CVE Program has not been renewed.

The funding cut for the 25 year old CVE program — which is globally relied upon to identify and mitigate security flaws — is part of a cost-cutting drive by the Trump administration.

The move to cut CVE funding is certainly a concern — especially given how suddenly it seems to have happened. Here is what happened, what it means for global security and what to do next,

What Happened And Why?

MITRE vice president Yosry Barsoum confirmed that U.S. government funding for the CVE database and the Common Weaknesses Enumeration programs will expire now, warning that it could be a disaster for security. The news came via a letter on social network BlueSky.

“On Wednesday, April 16, 2025, the current contracting pathway for MITRE to develop, operate, and modernize CVE and several other related programs, such as CWE, will expire,” Barsoum wrote in a letter published on Bluesky.

“If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of critical infrastructure.”

It comes as the U.S. Department of Homeland Security’s national security research subdivision, the Science and Technology Directorate, will stop current grants and refocus its mission priorities.

“CISA is the primary sponsor for the CVE program, which is used by government and industry alike to disclose, catalog, and share information on technology vulnerabilities that can put the nation’s critical infrastructure at risk,” a CISA spokesperson told me via email.

Although CISA’s contract with the MITRE Corporation will lapse after Apr. 16, CISA said it is “urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely.”

Why Is The Cut To CVE Funding Bad?

Known by all in the security community inside the U.S. and out, the CVE system is a global reference method for publicly-known security flaws.

Launched in 1999, the CVE system is maintained by the U.S. National Cybersecurity FFRDC, operated by The MITRE Corporation, with funding from the US National Cyber Security Division of the US Department of Homeland Security.

CVE IDs are listed on MITRE’s system as well as in the U.S. National Vulnerability Database.

The CVE database is “critical for anyone doing vulnerability management or security research,” and for “a whole lot of other uses,” security journalist Brian Krebbs wrote on Mastodon. “There isn’t really anyone else left who does this, and it’s typically been work that is paid for and supported by the U.S. government, which is a major consumer of this information, btw.”

America’s abrupt pullback from leadership roles “in this case coordinating the near global issue of CVEs for vulnerabilities” will “place a heavy burden on global cyber defenses,” says Ian Thornton-Trump, CISO at Inversion6.

It will impact global response capabilities to CVE exploitation such as “HeartBleed” among vulnerability and attack surface management companies, says Thornton-Trump.

Thornton-Trump concedes the immediate impacts might be “minimal” but says the move is now “helpful to our adversaries.”

Cutting the CVE program funding is “a huge blow to the cybersecurity community,” says William Wright, CEO of penetration testing firm, Closed Door Security. “Many of today’s ransomware attacks and data breaches are executed by adversaries exploiting vulnerabilities. Without a common destination to log vulnerabilities, so organizations can take steps to patch them, they could be more vulnerable to attack.”

The CVE Funding Cut’s Impact On Global Cybersecurity

However, the news might not be quite as bad as it seems. It’s important to understand that MITRE does not operate the National Vulnerability Database, this is run by the U.S. National Institute of Standards and Technology, says Sean Wright, an independent security researcher. “This is an important distinction since most vulnerability scanners use the NVD as the source of vulnerabilities to do their scanning.”

While MITRE does assign CVEs IDs, there are also CVE Naming Authority, that can also assign CVE IDs, says Wright. “It is important to note that while MITRE is the source of CVE IDs, most security tooling leverages the National Vulnerability Database for their source of vulnerabilities. This is operated by NIST, and to the best of our knowledge at this time, the operation of this database will not be impacted.”

He says the recent news about MITRE’s contract would likely only affect new vulnerabilities. “Historical vulnerabilities should not be affected. It’s important to call this distinction out, as there’s already been some confusion.”

The question remains if the contract for MITRE is not renewed, how or if the organization will continue the CVE program, asks Wright, “Given that we now have a larger number of CVE numbering authorities now also issuing CVEs, it is possible that the impact of this recent news may not be as big as first thought. However with the limited information that we have, it’s not possible to tell.”

CVE Funding Cut — What To Do Next

MITRE said historical CVE records will be available on GitHub, but future CVEs still hang in the balance.

Hopefully another organization will step in to provide the funding, or countries will band together to offer support, says Closed Door Security’s Wright. “But until then, the world may have lost one of its greatest security resources.”

It is possible funding will move to one of the big players in global cybersecurity, or perhaps a consortium. “The health of the CVE MITRE database is undoubtedly of global benefit,” says Matt Saunders, DevOps lead at The Adaptavist Group. “There’s an opportunity here for the private sector, who will benefit the most from this, to step up and keep it going in the public interest — though there are also inevitable concerns around it falling into the hands of a single private entity.”

Businesses can prepare by diversifying their threat intelligence sources and monitoring vendor-specific vulnerability feeds, says Jamie Akhtar, CEO and co-founder at cybersecurity outfit CyberSmart. “Organizations should lean more heavily on resources like CISA’s Known Exploited Vulnerabilities list, the NVD (if it remains online), and coordinate closely with software vendors. However, there is no true replacement for CVE.”

For now, the best thing to do is hold tight and use the resources available to you. The CVE funding cut isn’t the end of the world, but it’s still a worrying move that potentially reduces security for everyone.

CVE database CVE funding CVE MITRE CVE news CVE program CVE program funding cut CVE shutdown CVE Trump Mitre funding What is Mitre
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 2025
Google’s Play Update—Bad News For Most Samsung Users

Google’s Play Update—Bad News For Most Samsung Users

13 December 2025
WWE SmackDown December 12, 2025 Results: Highlights And Takeaways

WWE SmackDown December 12, 2025 Results: Highlights And Takeaways

13 December 2025
‘NYT Mini’ Clues And Answers For Saturday, December 13

‘NYT Mini’ Clues And Answers For Saturday, December 13

13 December 2025
Pixel 10a Specs Leak, Magic8 Pro Launch, Google’s Emoji Update

Pixel 10a Specs Leak, Magic8 Pro Launch, Google’s Emoji Update

13 December 2025
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
John Summit went from working 9 a.m. to 9 p.m. in a ,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

John Summit went from working 9 a.m. to 9 p.m. in a $65,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

18 October 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Gen Z is drinking 20% less than Millennials. Productivity is rising. Coincidence? Not quite

Gen Z is drinking 20% less than Millennials. Productivity is rising. Coincidence? Not quite

13 December 20250 Views
Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

13 December 20250 Views
This CEO went back to college at 52, but says successful Gen Zers ‘forge their own path’

This CEO went back to college at 52, but says successful Gen Zers ‘forge their own path’

13 December 20250 Views
It’s a sequel, it’s a remake, it’s a reboot: Lawyers grow wistful for old corporate rumbles as Paramount, Netflix fight for Warner

It’s a sequel, it’s a remake, it’s a reboot: Lawyers grow wistful for old corporate rumbles as Paramount, Netflix fight for Warner

13 December 20252 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
SpaceX sets 0 billion valuation, confirms 2026 IPO plans

SpaceX sets $800 billion valuation, confirms 2026 IPO plans

13 December 2025
Apple Confirms iPhone Attacks—All Users Must Update Now

Apple Confirms iPhone Attacks—All Users Must Update Now

13 December 2025
Wisconsin couple’s ACA health plan soars from  a month to ,600 as subsidies expire

Wisconsin couple’s ACA health plan soars from $2 a month to $1,600 as subsidies expire

13 December 2025
Most Popular
Samsung Galaxy S26 Release Date: What’s Happening In May?

Samsung Galaxy S26 Release Date: What’s Happening In May?

13 December 20250 Views
Gen Z is drinking 20% less than Millennials. Productivity is rising. Coincidence? Not quite

Gen Z is drinking 20% less than Millennials. Productivity is rising. Coincidence? Not quite

13 December 20250 Views
Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

Banking on carbon markets 2.0: why financial institutions should engage with carbon credits

13 December 20250 Views
© 2025 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.