April 16, 2025
For over two decades, the Common Vulnerabilities and Exposures (CVE) program has been a cornerstone of cybersecurity. It provides a standardized system for identifying and cataloging publicly disclosed vulnerabilities. Managed by MITRE, the program has let organizations worldwide track, prioritize, and remediate security flaws effectively.
As of today, April 16, 2025, that program faces an uncertain future. Its federal funding has expired.
The funding crisis
MITRE confirmed that its contract with the U.S. Department of Homeland Security (DHS) - the contract that funds MITRE to develop, operate, and modernize the CVE program - expired today, April 16.
Yosry Barsoum, MITRE's Vice President and Director of the Center for Securing the Homeland, confirmed that funding for MITRE to run and modernize both the CVE program and related programs, such as the Common Weakness Enumeration (CWE) Program, would lapse as of that date.
The expiration means MITRE can no longer assign new CVE identifiers or maintain the CVE database. That could disrupt how vulnerabilities are tracked and managed worldwide.
This isn't a hypothetical concern. MITRE has already sounded the alarm. In a memo obtained by The Record, MITRE stated that without immediate funding, it "will begin reducing operations and notifying key stakeholders of the program's deterioration."
Why this matters
At first glance, this may sound like a bureaucratic hiccup. It isn't. The implications are widespread.
The CVE program isn't just a registry of flaws. It's the central reference point for nearly every vulnerability scanner, threat report, and patching workflow in use today.
When a new vulnerability is discovered, it typically receives a CVE ID - an official label that lets security tools, analysts, and vendors track it. Without that ID, vulnerabilities may go untracked, remain unpatched, or get duplicated under conflicting labels across platforms.
As SecurityWeek reported, MITRE's internal communication warned that this gap could make it harder for researchers and vendors to report and coordinate disclosures effectively.
A breakdown in coordination
The CVE system also underpins global vulnerability coordination. Without a single source of truth, the landscape fractures: vendors start maintaining private CVE-like databases, researchers publish flaws without clear identifiers, and security teams struggle to prioritize threats.
CSO Online put it bluntly: the expiration left the program in limbo, with no clear sign of when - or if - a new contract would be signed.
And it's not just about future vulnerabilities. Security teams' daily work already depends on CVEs to drive detection logic, prioritize risk, and kick off remediation. Without ongoing updates, even current tools will start to degrade.
MITRE warns of service disruptions
MITRE isn't sugarcoating the situation. In a public update, the organization confirmed that funding had run out. Unless a new contract is signed, it will stop assigning CVEs to newly discovered vulnerabilities starting this week.
This marks a turning point. The idea of CVEs being unavailable, or only inconsistently available, was once unthinkable. Now it's reality.
A bigger problem in a bigger system
At its core, this isn't just about funding a database. It's about the fragility of the systems the cybersecurity community relies on for coordination.
As Tenable pointed out, the CVE program had been under strain for years already - weighed down by outdated processes, rising disclosure volumes, and bureaucratic delays.
The fact that critical infrastructure like this can be paused over a missed contract renewal raises serious questions. Who owns the responsibility of keeping it running? And what happens when trust in a central authority erodes?
What comes next?
There are two likely paths. Either the government reinstates funding and the CVE program resumes with minimal downtime, or the industry enters a phase of disorganized tracking - with private entities scrambling to build their own registries, creating inconsistencies and duplication along the way.
Neither outcome solves the root problem: the global cybersecurity ecosystem's dependence on a single, underfunded point of failure.
The CVE program's lapse is a wake-up call - not just for government, but for the industry as a whole. Coordination, transparency, and shared knowledge aren't luxuries. They're prerequisites for resilience.
What security teams should do now
Until funding is restored, expect slower or paused issuance of new CVEs. In practice, that means:
- Vendors may publish vulnerabilities without a CVE ID
- Automated scanners may miss untracked flaws
- Patch prioritization systems could become outdated
- Researcher coordination may suffer from duplication or conflicting naming
Security teams need to adapt now. Manual correlation of vendor advisories, real-time threat feeds, and added context will be critical in the meantime.
How Vicarius supports its customers amid CVE program uncertainty
At Vicarius, we understand how critical the CVE program is to cybersecurity operations. In light of the current funding challenges, we're committed to keeping our customers' vulnerability management services running without interruption.
Our platform draws on multiple data sources and proprietary algorithms to identify and prioritize vulnerabilities. This lets organizations maintain a strong security posture even without new CVE entries. We're actively monitoring the situation and will adapt our systems as needed to keep protecting our clients.
As new developments emerge, we'll update this blog post accordingly.
Related resources: CVE research vRx product tour
Update - April 17
In a last-minute decision, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) extended MITRE's contract to manage the CVE program, ensuring uninterrupted service.
CISA explained that it had executed the contract's option period overnight, specifically to prevent any lapse in critical CVE services. The extension came just hours before the contract's expiration, easing concerns about potential disruptions to global cybersecurity coordination.
The renewed contract runs for 11 months, providing continued support for this vital cybersecurity resource.
Related resources:
CVE research
.avif)















.webp)








































%20Signals%20a%20New%20Era%20of%20Supply%20Chain%20Risk.webp)












.webp)























%20to%20Reduce%20Attack%20Surface.avif)



.avif)





