ECSO Calls for European Leadership in Vulnerability Management Following CVE Program Concerns
The European Cyber Security Organisation (ECSO) has expressed significant concern regarding recent developments in MITRE’s role overseeing the Common Vulnerabilities and Exposures (CVE) programme’s identification system.
The importance of a reliable vulnerability numbering system cannot be overstated for the international cybersecurity community. Without effective management of vulnerability identifiers, security for critical infrastructure, systems, and products faces serious risk. Both private and public organizations will encounter substantial challenges in:
ECSO believes this situation presents a crucial opportunity for European cybersecurity professionals to establish a viable alternative solution. Given the strategic importance of CVEs, ECSO advocates for creating a public-private partnership to assign and manage vulnerability identifiers both within Europe and globally. Such an initiative would strengthen Europe’s cybersecurity posture while ensuring European leadership in this critical domain.
ECSO Members and the ECSO CISO Community have expressed their readiness to support European initiatives aimed at developing a more transparent, trustworthy, and independent vulnerability ecosystem.
The European Cyber Security Organisation (ECSO) is the pan-European, private-public federation (non-profit) dedicated to developing Europe’s cybersecurity resilience and strategic autonomy. Established in 2016 as the European Commission’s contractual partner for the Public-Private Partnership in Cybersecurity, ECSO unites more than 320 stakeholders—including businesses of all sizes, public administrations, research centers, and other organizations. The organization provides a platform for dialogue, knowledge sharing, visibility opportunities, industry advocacy, and enhanced public-private collaboration.