VYPR
advisoryPublished Aug 10, 2026· 1 source

NATO and AI Startup Gain CVE Authority to Track Software Flaws

NATO's cyber defense arm and AI startup AISLE have become CVE Numbering Authorities (CNAs) under ENISA, enhancing global vulnerability tracking and disclosure processes.

NATO's cyber defense arm, the NATO Cyber Security Centre, and AI-powered cybersecurity firm AISLE have officially been designated as CVE Numbering Authorities (CNAs) under the European Union Agency for Cybersecurity (ENISA) Root. This significant development allows both organizations to assign unique CVE IDs to newly discovered software vulnerabilities, a crucial step in standardizing and accelerating the tracking and management of security flaws.

The CVE (Common Vulnerabilities and Exposures) program provides a universally recognized identifier for each publicly disclosed security vulnerability. By becoming CNAs, the NATO Cyber Security Centre and AISLE can now directly issue these identifiers, streamlining the disclosure process and improving information sharing within their respective domains and with global partners. This expansion under ENISA's purview aims to bolster the global vulnerability management ecosystem, particularly as artificial intelligence plays an increasingly prominent role in discovering new flaws.

The NATO Cyber Security Centre's new authority will enable it to assign CVE IDs to vulnerabilities affecting the alliance's extensive networks and systems. This will lead to more consistent tracking of security weaknesses across NATO's infrastructure and facilitate faster, more coordinated information sharing with trusted allies. The center, responsible for guarding NATO's networks, monitoring threats, and coordinating incident responses, will leverage this designation to enhance its defensive posture.

AISLE's designation as a CNA is more focused, primarily covering vulnerabilities discovered within its own products. This allows the company to manage the disclosure of flaws in its AI-driven security solutions more efficiently, without needing to rely on third-party authorities for CVE assignment. Jaya Baloo, co-founder of AISLE, emphasized the foundational importance of this step, stating that coordinated disclosure begins with holding one's own products to the highest standards.

This move comes at a critical juncture for the CVE program, which has faced recent challenges, including near-shutdowns and the emergence of competing vulnerability tracking initiatives. The growing volume of vulnerabilities discovered by AI systems further underscores the need for robust and scalable vulnerability management infrastructure. ENISA's role in expanding the number of CNAs aims to create a more globally representative and resilient system for identifying and addressing security weaknesses.

While AISLE can now manage its own product vulnerabilities, its researchers have also been active in disclosing numerous flaws in widely used open-source software, such as OpenSSL, Linux, and Apache, through the appropriate CNAs for those projects. This dual approach highlights the collaborative nature of vulnerability management, even as organizations gain more direct control over their own disclosures.

The integration of AI in vulnerability discovery is a rapidly evolving area. Organizations like NATO and companies like AISLE are adapting their processes to keep pace with the increasing speed and sophistication of threat discovery. By becoming CNAs, they are positioning themselves to better manage the lifecycle of vulnerabilities, from identification to remediation, in an increasingly complex threat landscape.

This expansion of CVE authority signifies a broader trend towards decentralization and increased participation in vulnerability management. As more entities gain the ability to assign CVE IDs, the global community can expect a more comprehensive and timely approach to addressing software security flaws, particularly those uncovered by advanced technologies like artificial intelligence.

Synthesized by Vypr AI