NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week.
The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company with offices in San Francisco and Prague, joined as CVE numbering authorities under the ENISA Root. The CVE program assigns a unique record to each publicly disclosed security flaw so that governments, vendors and researchers have a common marker when referring to particular vulnerabilities.
Twenty numbering authorities now sit under the ENISA Root, with 12 brought in by ENISA itself and eight moving over from the MITRE Root, run by the U.S. nonprofit that has handled the program’s daily work for more than 20 years.
Hans de Vries, ENISA’s chief cybersecurity and operations officer, linked the growth to changes in how people find flaws.
“Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities,” he said in a statement. He said ENISA’s role helps build a “more globally representative, resilient, and scalable vulnerability identification ecosystem.”
The two new members show how bespoke each member is within its authority. The NATO Cyber Security Centre can now assign CVE IDs to eligible flaws across the NATO enterprise. The agency said that will make tracking more consistent and let the alliance share information with trusted partners sooner. The center guards NATO’s networks, watches for threats and coordinates the response when incidents hit.
Meanwhile, AISLE’s authorization is narrower. The company said in a July press release that the designation covers vulnerabilities discovered in its own products, allowing it to publish identifiers without waiting for a third-party authority to process a request.
Jaya Baloo, the company’s co-founder, described the step as “foundational” and said coordinated disclosure “starts with holding your own products to the same standard you expect of everyone else.” Separately from the designation, the company said its researchers have disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache and OpenEMR, each coordinated through the relevant authority for that project.
The changes come as the CVE process continues to involve amid program upheaval and the torrent of vulnerabilities discovered by AI systems.
The CVE program, run by CISA, narrowly escaped a sudden demise when a last-minute, 11-month contract extension averted a shutdown in April 2025. Since then, several competing databases from European nonprofits and other private entities have been stood up in order to better coordinate how vulnerabilities are tracked, disclosed, and ultimately patched.
Earlier this year, The Computer Incident Response Center Luxembourg (CIRCL) launched the Global CVE Allocation System, or GCVE, as an alternative to the CVE program.
The post NATO and an AI startup can now name and track software vulnerabilities appeared first on CyberScoop.