Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch
News

Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch

Team-CWDBy Team-CWDJanuary 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new community-driven, European-headquartered alternative to the US-led Common Vulnerabilities and Exposures (CVE) program has been welcome by security experts.

The open source Global Cybersecurity Vulnerability Enumeration (GCVE) initiative brings together vulnerability information from over 25 public sources. These include GCVE Numbering Authorities (GNAs), which are able to allocate and publish vulnerability identifiers independently.

“By enabling GNAs and other publishers to contribute data independently, while still benefiting from global correlation, GCVE aims to reduce single points of failure and foster innovation in vulnerability management,” the GCVE said.

“The goal of db.gcve.eu is to provide the community with a single, unified, and openly accessible reference point for vulnerability intelligence, enabling defenders, researchers, CSIRTs, vendors, and open-source projects to more easily track, correlate, and analyze security advisories across ecosystems.”

The idea is to create a vulnerability identification, disclosure and publication ecosystem that is decentralized and resilient – with the db.gcve.eu platform hosted and operated by the Computer Incident Response Center Luxembourg (CIRCL).

“This ensures full control over the infrastructure, data, and operations. By combining open-source software, open data, and European-controlled infrastructure, GCVE and CIRCL contribute to strengthening digital sovereignty, strategic autonomy, and trust in vulnerability information sharing,” the GCVE added.

Concerns Over US Funding

The model stands in stark contrast to the centralized CVE program, run by American non-profit MITRE. It suffered a period of intense uncertainty last year after the Trump administration’s Department of Government Efficiency (DOGE) cancelled more than $28m in MITRE contracts.

In the end, the US Cybersecurity and Infrastructure Security Agency (CISA) stepped in at the last minute to save the program, announcing an 11-month contract extension.

However, the existential crisis this provoked was too close a call for many in the cybersecurity community, leading many to look for alternatives.

Closed Door Security CEO, William Wright, welcomed the launch of the GCVE in this regard.

“The establishment of another major program prevents the shutdown of the CVE program from becoming a single point of failure,” he argued.

“The establishment of the GCVE also pre-empts the uncertainty surrounding the continued funding of the CVE program, and, should it ever be shut down, the GCVE system would provide an alternative on which cybersecurity researchers and professionals could immediately rely.”

Wright also pointed to mounting concerns about the speed and efficacy of the CVE program, and the ability of MITRE and NIST, which runs the National Vulnerability Database, to keep up with a fast-moving threat landscape.

“The new EU program is designed to be decentralized and cross-compatible with CVE, supplementing and normalizing data from multiple sources, and allowing for vulnerabilities to be documented and published by designated GNAs, without the need for central approval,” he said.

“Hopefully, this should allow for a faster and more robust documentation process, and should enable governments and businesses to respond more quickly to serious threats.”

Natalie Page, head of threat intelligence at Talion, praised the launch of the GCVE in similar terms.

“By diversifying the CVE program, this means the world is no longer reliant solely on a single body for ratings and disclosures,” she said. “However, the one caveat to the program is that it should aim to not confuse organisations or cause misalignment with CVE tracking. It should aim to be compatible with the US CVE program, using similar language and ratings.”

A separate European Vulnerability Database (EUVD) initiative also launched last year.

Read more on the CVE program: NIST Confusion Continues as Cyber Pros Complain CVE Uploads Stalled



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChina-Linked APT Exploited Sitecore Zero-Day in Critical Infrastructure Intrusions
Next Article LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What it is and how to protect yourself

January 8, 2026

Can password managers get hacked? Here’s what to know

November 14, 2025

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.