Vulnerabilities

CISA Announces CVE Enrichment Project ‘Vulnrichment’

CISA’s Vulnrichment project is adding important information to CVE records to help improve vulnerability management processes.

CISA

The US cybersecurity agency CISA on Wednesday announced a new project that aims to add important information to CVE records in an effort to help organizations improve their vulnerability management processes.

The project is named Vulnrichment and its goal is the enrichment of public CVE records with Common Platform Enumeration (CPE), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE), and Known Exploited Vulnerabilities (KEV) data.

CISA says it has already enriched 1,300 CVEs — particularly new and recent CVEs — and is asking all CVE numbering authorities (CNAs) to provide complete information when submitting vulnerability information to CVE.org. 

The agency says it’s initially taking each CVE through a Stakeholder-Specific Vulnerability Categorization (SSVC) scoring process. 

SSVC, developed by CISA in collaboration with Carnegie Mellon University’s Software Engineering Institute, provides a vulnerability analysis methodology that accounts for a vulnerability’s exploitation status, safety impact, and prevalence of the affected product.

In the next phase, further analysis is conducted for vulnerabilities that have a high-impact, are automatable, have PoC exploit code available, or are already being exploited in attacks.  

Advertisement. Scroll to continue reading.

CISA says the information added as part of the Vulnrichment project can help organizations prioritize remediation efforts and understand trends, and it can drive vendors to address entire classes of vulnerabilities.

The Vulnrichment project is hosted on GitHub and each enriched CVE entry is available in JSON format to allow organizations to easily incorporate the updates into their vulnerability management processes. 

CISA is often the first to issue public warnings about a vulnerability being exploited in the wild. The agency’s KEV catalog, which includes over 1,100 exploited flaw entries, has become an important resource for vulnerability management.

Related: Zoom Unveils Open Source Vulnerability Impact Scoring System

Related: Faster Patching Pace Validates CISA’s KEV Catalog Initiative

Related: CISA Releases Decision Tree Model to Help Companies Prioritize Vulnerability Patching

Related Content

Artificial Intelligence

AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact. 

Application Security

It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities.

ICS/OT

CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.

Vulnerabilities

The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects.

Vulnerabilities

The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities.

Vulnerabilities

More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution.

Vulnerabilities

The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands.

Application Security

The security defects allow unauthenticated users to take control of the open source software supply chain.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version