people, THIS is big and you need it in front of management RIGHT NOW.

MITRE has informed the CVE board members that effective TONIGHT, funding to run CVE and CWE is effectively gone. The US federal government contracts MITRE to run these programs including both management, operations, and infrastructure.

This not only could but almost certainly will result in disruptions to CVE and CWE including a halt of all operations if new contracts/funding are not secured.

MITRE β€˜ SOLVING PROBLEMS FOR A SAFER WORLD" April 15, 2025 
Dear CVE Board Member, 
We want to make you aware of an important potential issue with MITRE’s enduring support to CVE. On Wednesday, April 16, 2025, the current contracting pathway for MITRE to develop, operate, and modernize CVE and several other related programs, such as CWE, will expire. The government continues to make considerable efforts to continue MITRE's role in support of the program If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of citical infrastructure. MITRE continues to be committed to CVE as a global resource. We thank you as a member of the CVE Board for your continued partnership. 

Sincerely, Yosry Barsoum 
VP and Director
Center for Securing the Homeland (CSH)
0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://weird.autos/users/rootwyrm/statuses/114343301792346250 on your instance and quote it. (Note that quoting is not supported in Mastodon.)