IT & Security

What Happens When the CVE Program Runs Out of Cash

April 16, 2025
Even as the future of the CVE program remains uncertain, Vicarius ensures business as usual. With multiple data sources and proprietary detection methods, our platform continues to deliver real-time, uninterrupted vulnerability and remediation management, no matter what. We’ve got you covered.

April 16, 2025

For over two decades, the Common Vulnerabilities and Exposures (CVE) program has been a cornerstone of cybersecurity. It provides a standardized system for identifying and cataloging publicly disclosed vulnerabilities. Managed by MITRE, the program has let organizations worldwide track, prioritize, and remediate security flaws effectively.

As of today, April 16, 2025, that program faces an uncertain future. Its federal funding has expired.

The funding crisis

MITRE confirmed that its contract with the U.S. Department of Homeland Security (DHS) - the contract that funds MITRE to develop, operate, and modernize the CVE program - expired today, April 16.

Yosry Barsoum, MITRE's Vice President and Director of the Center for Securing the Homeland, confirmed that funding for MITRE to run and modernize both the CVE program and related programs, such as the Common Weakness Enumeration (CWE) Program, would lapse as of that date.

The expiration means MITRE can no longer assign new CVE identifiers or maintain the CVE database. That could disrupt how vulnerabilities are tracked and managed worldwide.

This isn't a hypothetical concern. MITRE has already sounded the alarm. In a memo obtained by The Record, MITRE stated that without immediate funding, it "will begin reducing operations and notifying key stakeholders of the program's deterioration."

Why this matters

At first glance, this may sound like a bureaucratic hiccup. It isn't. The implications are widespread.

The CVE program isn't just a registry of flaws. It's the central reference point for nearly every vulnerability scanner, threat report, and patching workflow in use today.

When a new vulnerability is discovered, it typically receives a CVE ID - an official label that lets security tools, analysts, and vendors track it. Without that ID, vulnerabilities may go untracked, remain unpatched, or get duplicated under conflicting labels across platforms.

As SecurityWeek reported, MITRE's internal communication warned that this gap could make it harder for researchers and vendors to report and coordinate disclosures effectively.

A breakdown in coordination

The CVE system also underpins global vulnerability coordination. Without a single source of truth, the landscape fractures: vendors start maintaining private CVE-like databases, researchers publish flaws without clear identifiers, and security teams struggle to prioritize threats.

CSO Online put it bluntly: the expiration left the program in limbo, with no clear sign of when - or if - a new contract would be signed.

And it's not just about future vulnerabilities. Security teams' daily work already depends on CVEs to drive detection logic, prioritize risk, and kick off remediation. Without ongoing updates, even current tools will start to degrade.

MITRE warns of service disruptions

MITRE isn't sugarcoating the situation. In a public update, the organization confirmed that funding had run out. Unless a new contract is signed, it will stop assigning CVEs to newly discovered vulnerabilities starting this week.

This marks a turning point. The idea of CVEs being unavailable, or only inconsistently available, was once unthinkable. Now it's reality.

A bigger problem in a bigger system

At its core, this isn't just about funding a database. It's about the fragility of the systems the cybersecurity community relies on for coordination.

As Tenable pointed out, the CVE program had been under strain for years already - weighed down by outdated processes, rising disclosure volumes, and bureaucratic delays.

The fact that critical infrastructure like this can be paused over a missed contract renewal raises serious questions. Who owns the responsibility of keeping it running? And what happens when trust in a central authority erodes?

What comes next?

There are two likely paths. Either the government reinstates funding and the CVE program resumes with minimal downtime, or the industry enters a phase of disorganized tracking - with private entities scrambling to build their own registries, creating inconsistencies and duplication along the way.

Neither outcome solves the root problem: the global cybersecurity ecosystem's dependence on a single, underfunded point of failure.

The CVE program's lapse is a wake-up call - not just for government, but for the industry as a whole. Coordination, transparency, and shared knowledge aren't luxuries. They're prerequisites for resilience.

What security teams should do now

Until funding is restored, expect slower or paused issuance of new CVEs. In practice, that means:

  • Vendors may publish vulnerabilities without a CVE ID
  • Automated scanners may miss untracked flaws
  • Patch prioritization systems could become outdated
  • Researcher coordination may suffer from duplication or conflicting naming

Security teams need to adapt now. Manual correlation of vendor advisories, real-time threat feeds, and added context will be critical in the meantime.

How Vicarius supports its customers amid CVE program uncertainty

At Vicarius, we understand how critical the CVE program is to cybersecurity operations. In light of the current funding challenges, we're committed to keeping our customers' vulnerability management services running without interruption.

Our platform draws on multiple data sources and proprietary algorithms to identify and prioritize vulnerabilities. This lets organizations maintain a strong security posture even without new CVE entries. We're actively monitoring the situation and will adapt our systems as needed to keep protecting our clients.

As new developments emerge, we'll update this blog post accordingly.

Related resources: CVE research vRx product tour

Update - April 17

In a last-minute decision, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) extended MITRE's contract to manage the CVE program, ensuring uninterrupted service.

CISA explained that it had executed the contract's option period overnight, specifically to prevent any lapse in critical CVE services. The extension came just hours before the contract's expiration, easing concerns about potential disruptions to global cybersecurity coordination.

The renewed contract runs for 11 months, providing continued support for this vital cybersecurity resource.

Related resources:
CVE research

vRx product tour

Sagy Kratu

Sr. Product Marketing Manager

Subscribe for more

Get more infosec news and insights.

Related articles

1000+ members

Turn security converstains into remediation actions