The NATO Cyber Security Centre and the AI-driven cybersecurity firm AISLE have been designated as CVE Numbering Authorities (CNAs) under the European Union Agency for Cybersecurity (ENISA) Root. This designation allows both entities to assign unique CVE (Common Vulnerabilities and Exposures) identifiers to newly discovered software vulnerabilities, streamlining the process of tracking and communicating security flaws.
The NATO Cyber Security Centre, which is part of the NATO Communications and Information Agency, will now be able to assign CVE IDs for eligible vulnerabilities found within the NATO enterprise. This capability is expected to enhance consistency in vulnerability tracking and facilitate faster information sharing with trusted partners across the alliance. The center's responsibilities include safeguarding NATO's networks, monitoring for threats, and coordinating incident responses.
AISLE, a cybersecurity company with offices in San Francisco and Prague, has a more specific authorization. Its CNA designation primarily covers vulnerabilities discovered in its own products. This allows the company to publish identifiers directly without needing to wait for a third-party authority to process a request. The company's co-founder noted that this step is foundational for coordinated disclosure, emphasizing the importance of applying the same security standards to one's own products as expected from others. Separately, AISLE researchers have reportedly disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache, and OpenEMR, coordinating each through the relevant project's authority.
ENISA's chief cybersecurity and operations officer, Hans de Vries, highlighted that the expansion of CNAs, particularly with the addition of NATO and AISLE, reflects the evolving landscape of cybersecurity. He specifically cited the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation as a key factor driving the need for robust vulnerability management infrastructure. ENISA's role, he stated, contributes to building a more globally representative, resilient, and scalable ecosystem for vulnerability identification.
With these additions, the ENISA Root now oversees twenty CNAs. Twelve of these were brought in directly by ENISA, while eight transitioned from the MITRE Root, which has managed the CVE program's daily operations for over two decades. The CVE program itself, run by CISA, faced potential disruption in April 2025 but was sustained by an 11-month contract extension. In the interim, several alternative vulnerability databases have emerged from European nonprofits and private entities, aiming to improve coordination in tracking, disclosing, and patching vulnerabilities. For example, The Computer Incident Response Center Luxembourg (CIRCL) recently launched the Global CVE Allocation System (GCVE) as an alternative to the existing CVE program.






