diff --git a/public/images/news/VulnCon_AZ.png b/public/images/news/VulnCon_AZ.png new file mode 100644 index 00000000..f14d4291 Binary files /dev/null and b/public/images/news/VulnCon_AZ.png differ diff --git a/src/assets/data/CNAsList.json b/src/assets/data/CNAsList.json index 5809be82..5b962ded 100644 --- a/src/assets/data/CNAsList.json +++ b/src/assets/data/CNAsList.json @@ -13965,7 +13965,7 @@ { "label": "Policy", "language": "", - "url": "https://grafana.com/security.txt" + "url": "https://grafana.com/legal/report-a-security-issue/" } ], "securityAdvisories": { @@ -15864,7 +15864,7 @@ { "label": "Policy", "language": "", - "url": "https://www.blacklanternsecurity.com/cna.html" + "url": "https://www.blacklanternsecurity.com/disclosure-policy/" } ], "securityAdvisories": { @@ -23496,7 +23496,7 @@ { "label": "Policy", "language": "", - "url": "https://static.omnissa.com/uploads/omnissa-external-vulnerability-response-and-remediation-policy.pdf" + "url": "https://www.omnissa.com/omnissa-external-vulnerability-response-and-remediation-policy/" } ], "securityAdvisories": { @@ -29702,5 +29702,229 @@ ] }, "country": "USA" + }, + { + "shortName": "Cynet", + "cnaID": "CNA-2026-0036", + "organizationName": "Cynet Security Inc.", + "scope": "Vulnerabilities in Cynet Security products and services, including the Cynet 360 All in one platform, endpoint agents (Windows, macOS, Linux), Cynet-managed APIs, web applications, and internet-facing infrastructure operated by Cynet Security.", + "contact": [ + { + "email": [ + { + "label": "Email", + "emailAddr": "responsible-disclosure@cynet.com" + } + ], + "contact": [], + "form": [] + } + ], + "disclosurePolicy": [ + { + "label": "Policy", + "language": "", + "url": "https://www.cynet.com/cynet-responsible-disclosure-policy/" + } + ], + "securityAdvisories": { + "alerts": [], + "advisories": [ + { + "label": "Advisories", + "url": "https://www.cynet.com/blog/" + } + ] + }, + "resources": [], + "CNA": { + "isRoot": false, + "root": { + "shortName": "n/a", + "organizationName": "n/a" + }, + "roles": [ + { + "helpText": "", + "role": "CNA" + } + ], + "TLR": { + "shortName": "mitre", + "organizationName": "MITRE Corporation" + }, + "type": [ + "Vendor" + ] + }, + "country": "USA" + }, + { + "shortName": "linqi", + "cnaID": "CNA-2026-0037", + "organizationName": "linqi GmbH", + "scope": "Vulnerabilities in linqi products only.", + "contact": [ + { + "email": [ + { + "label": "Email", + "emailAddr": "security@linqi.de" + } + ], + "contact": [], + "form": [] + } + ], + "disclosurePolicy": [ + { + "label": "Policy", + "language": "", + "url": "https://linqi.help/en/reference/security/vulnerability-disclosure-policy" + } + ], + "securityAdvisories": { + "alerts": [], + "advisories": [ + { + "label": "Advisories", + "url": "https://linqi.help/en/reference/security/security-advisories" + } + ] + }, + "resources": [], + "CNA": { + "isRoot": false, + "root": { + "shortName": "n/a", + "organizationName": "n/a" + }, + "roles": [ + { + "helpText": "", + "role": "CNA" + } + ], + "TLR": { + "shortName": "mitre", + "organizationName": "MITRE Corporation" + }, + "type": [ + "Vendor" + ] + }, + "country": "Germany" + }, + { + "shortName": "OMICRON", + "cnaID": "CNA-2026-0038", + "organizationName": "OMICRON electronics", + "scope": "OMICRON electronics issues only.", + "contact": [ + { + "email": [ + { + "label": "Email", + "emailAddr": "product.security@omicronenergy.com" + } + ], + "contact": [], + "form": [] + } + ], + "disclosurePolicy": [ + { + "label": "Policy", + "language": "", + "url": "https://www.omicronenergy.com/security/" + } + ], + "securityAdvisories": { + "alerts": [], + "advisories": [ + { + "label": "Advisories", + "url": "https://www.omicronenergy.com/security/" + } + ] + }, + "resources": [], + "CNA": { + "isRoot": false, + "root": { + "shortName": "icscert", + "organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)" + }, + "type": [ + "Vendor" + ], + "TLR": { + "shortName": "CISA", + "organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)" + }, + "roles": [ + { + "helpText": "", + "role": "CNA" + } + ] + }, + "country": "Austria" + }, + { + "shortName": "IQSIGHT", + "cnaID": "CNA-2026-0039", + "organizationName": "IQSIGHT B.V.", + "scope": "All IQSIGHT (formerly Bosch Building Technology - Video Systems) products including end-of-life products.", + "contact": [ + { + "email": [ + { + "label": "Email", + "emailAddr": "psirt@iqsight.com" + } + ], + "contact": [], + "form": [] + } + ], + "disclosurePolicy": [ + { + "label": "Policy", + "language": "", + "url": "https://www.iqsight.com/en/support/product-security/" + } + ], + "securityAdvisories": { + "alerts": [], + "advisories": [ + { + "label": "Advisories", + "url": "https://www.iqsight.com/en/support/product-security/vulnerability-report/" + } + ] + }, + "resources": [], + "CNA": { + "isRoot": false, + "root": { + "shortName": "ENISA", + "organizationName": "EU Agency for Cybersecurity (ENISA)" + }, + "type": [ + "Vendor" + ], + "TLR": { + "shortName": "mitre", + "organizationName": "MITRE Corporation" + }, + "roles": [ + { + "helpText": "", + "role": "CNA" + } + ] + }, + "country": "Netherlands" } ] \ No newline at end of file diff --git a/src/assets/data/boardMeetings.json b/src/assets/data/boardMeetings.json index 88119535..7b45ff77 100644 --- a/src/assets/data/boardMeetings.json +++ b/src/assets/data/boardMeetings.json @@ -1,5 +1,9 @@ { "2026": [ + { + "name": "April 29, 2026 - teleconference", + "path": "msg00331.html" + }, { "name": "April 1, 2026 - teleconference", "path": "msg00326.html" diff --git a/src/assets/data/events.json b/src/assets/data/events.json index a1dea32e..416c110f 100644 --- a/src/assets/data/events.json +++ b/src/assets/data/events.json @@ -30,7 +30,7 @@ "id": 40, "title": "CVE/FIRST VulnCon 2026", "location": "Scottsdale, Arizona, USA & Virtual", - "description": "VulnCon is co-hosted by the CVE Program and FIRST and is open to the public.

Agenda:
Available on the conference web page or view the schedule by day:

Monday, April 13View day 1 schedule
Tuesday, April 14View day 2 schedule
Wednesday, April 15View day 3 schedule
Thursday, April 16View day 4 schedule

An Offsite Social Event will be held at the Western Spirit Museum on Wednesday, April 15. Learn more here.

Registration:
Closed on April 6, 2026, at 19:00 UTC. Learn more here. Registration fees include full admission to conference activities Monday through Thursday; continental breakfast, lunch, and two coffee breaks Tuesday through Thursday; entry to the Monday welcome reception; entry to the Tuesday networking reception; entry to the vendor hall; all applicable conference materials;, and access to live streams and applicable apps.

Purpose:
The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.

Call for Speakers (CFS):
Closed on December 22, 2025. The CFS requirements and submission process are available here.", + "description": "VulnCon is co-hosted by the CVE Program and FIRST and is open to the public. Watch session videos here.

Agenda:
Available on the conference web page or view the schedule by day:

Monday, April 13View day 1 schedule
Tuesday, April 14View day 2 schedule
Wednesday, April 15View day 3 schedule
Thursday, April 16View day 4 schedule

An Offsite Social Event will be held at the Western Spirit Museum on Wednesday, April 15. Learn more here.

Registration:
Closed on April 6, 2026, at 19:00 UTC. Learn more here. Registration fees include full admission to conference activities Monday through Thursday; continental breakfast, lunch, and two coffee breaks Tuesday through Thursday; entry to the Monday welcome reception; entry to the Tuesday networking reception; entry to the vendor hall; all applicable conference materials;, and access to live streams and applicable apps.

Purpose:
The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.

Call for Speakers (CFS):
Closed on December 22, 2025. The CFS requirements and submission process are available here.", "permission": "public", "url": "https://www.first.org/conference/vulncon26/", "date": { diff --git a/src/assets/data/metrics.json b/src/assets/data/metrics.json index 8f67b43e..0cd85b97 100644 --- a/src/assets/data/metrics.json +++ b/src/assets/data/metrics.json @@ -1235,7 +1235,7 @@ }, { "month": "June", - "value": "TBA" + "value": "4" }, { "month": "July", diff --git a/src/assets/data/news.json b/src/assets/data/news.json index 2dddf363..e15b1153 100644 --- a/src/assets/data/news.json +++ b/src/assets/data/news.json @@ -1,5 +1,186 @@ { "currentNews": [ + { + "id": 682, + "newsType": "news", + "title": "IQSIGHT Added as CVE Numbering Authority (CNA)", + "urlKeywords": "IQSIGHT Added as CNA", + "date": "2026-06-02", + "description": [ + { + "contentnewsType": "paragraph", + "content": "IQSIGHT B.V. is now a CVE Numbering Authority (CNA) for all IQSIGHT (formerly Bosch Building Technology - Video Systems) products including end-of-life products." + }, + { + "contentnewsType": "paragraph", + "content": "To date, 521 CNAs (518 CNAs and 3 CNA-LRs) from 43 countries and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. IQSIGHT is the 7th CNA from Netherlands." + }, + { + "contentnewsType": "paragraph", + "content": "IQSIGHT’s Root is the ENISA Root." + } + ] + }, + { + "id": 681, + "newsType": "news", + "title": "OMICRON electronics Added as CVE Numbering Authority (CNA)", + "urlKeywords": "OMICRON electronics Added as CNA", + "date": "2026-06-02", + "description": [ + { + "contentnewsType": "paragraph", + "content": "OMICRON electronics is now a CVE Numbering Authority (CNA) for OMICRON electronics issues only." + }, + { + "contentnewsType": "paragraph", + "content": "To date, 520 CNAs (517 CNAs and 3 CNA-LRs) from 43 countries and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. OMICRON electronics is the 5th CNA from Austria." + }, + { + "contentnewsType": "paragraph", + "content": "OMICRON electronics’s Root is the CISA ICS Root." + } + ] + }, + { + "id": 680, + "newsType": "news", + "title": "linqi Added as CVE Numbering Authority (CNA)", + "urlKeywords": "linqi Added as CNA", + "date": "2026-06-02", + "description": [ + { + "contentnewsType": "paragraph", + "content": "linqi GmbH is now a CVE Numbering Authority (CNA) for vulnerabilities in linqi products only." + }, + { + "contentnewsType": "paragraph", + "content": "To date, 519 CNAs (516 CNAs and 3 CNA-LRs) from 43 countries and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. linqi is the 25th CNA from Germany." + }, + { + "contentnewsType": "paragraph", + "content": "linqi’s Root is the MITRE Top-Level Root." + } + ] + }, + { + "id": 679, + "newsType": "news", + "title": "Cynet Security Added as CVE Numbering Authority (CNA)", + "urlKeywords": "Cynet Security Added as CNA", + "date": "2026-06-02", + "description": [ + { + "contentnewsType": "paragraph", + "content": "Cynet Security Inc. is now a CVE Numbering Authority (CNA) for vulnerabilities in Cynet Security products and services, including the Cynet 360 All in one platform, endpoint agents (Windows, macOS, Linux), Cynet-managed APIs, web applications, and internet-facing infrastructure operated by Cynet Security." + }, + { + "contentnewsType": "paragraph", + "content": "To date, 518 CNAs (515 CNAs and 3 CNA-LRs) from 43 countries and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Cynet Security is the 277th CNA from USA." + }, + { + "contentnewsType": "paragraph", + "content": "Cynet Security’s Root is the MITRE Top-Level Root." + } + ] + }, + { + "id": 678, + "newsType": "blog", + "title": "Vulnerability Data Enrichment for CVE Records: 259 CNAs on the Enrichment Recognition List for June 1, 2026", + "urlKeywords": "CNA Enrichment Recognition List Update", + "date": "2026-06-02", + "author": { + "name": "CVE Program", + "organization": { + "name": "CVE Program", + "url": "" + }, + "title": "", + "bio": "" + }, + "description": [ + { + "contentnewsType": "image", + "imageWidth": "", + "href": "/news/CnaEnrichmentRecognitionList.png", + "altText": "Increasing the Value of the CVE Record - CNA Enrichment Recognition List" + }, + { + "contentnewsType": "paragraph", + "content": "The “CNA Enrichment Recognition List” for June 1, 2026, is now available with 259 CNAs listed. Published monthly on the CVE website, the list recognizes those CVE Numbering Authorities (CNAs) that are actively providing enhanced vulnerability data in their CVE Records. CNAs are added to the list if they provide Common Vulnerability Scoring System (CVSS) and Common Weakness Enumeration (CWE™) in at least 98% of their records that were published within two weeks of their most recently published record." + }, + { + "contentnewsType": "paragraph", + "content": "CNA Enrichment Recognition List criteria and reporting are intended to recognize those CNAs taking on the work to increase the value of CVE Records for downstream consumers, and encourage others to do the same. Enrichment Recognition List criteria may change over time. The most recent modifications occurred in June 2025 when data pulls were moved from every two weeks and based upon data from the last 12 months, to the current reporting of once-per-month data pulls based upon data from the previous six months." + }, + { + "contentnewsType": "paragraph", + "content": "For more about the recognition list, see “Recognition for CNAs Actively Providing Vulnerability Data Enrichment for CVE Records.” To learn more about vulnerability information types like CVSS and CWE, see the CVE Record User Guide. View the most current CNA Enrichment Recognition List on the CVE website Metrics page here." + }, + { + "contentnewsType": "paragraph", + "content": "CNA Enrichment Recognition List for June 1, 2026, with 259 CNAs listed:
" + } + ] + }, + { + "id": 677, + "newsType": "blog", + "title": "Videos from CVE/FIRST VulnCon 2026 Now Available", + "urlKeywords": "Videos from VulnCon 2026 Now Available", + "date": "2026-06-02", + "author": { + "name": "CVE Program", + "organization": { + "name": "CVE Program", + "url": "" + }, + "title": "", + "bio": "" + }, + "description": [ + { + "contentnewsType": "image", + "imageWidth": "", + "href": "/news/VulnCon_AZ.png", + "altText": "VulnCon 2026" + }, + { + "contentnewsType": "paragraph", + "content": "Videos of fifty sessions from CVE/FIRST VulnCon 2026 are now available on the FIRST Channel on YouTube and the CVE Program Channel on YouTube. The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem." + }, + { + "contentnewsType": "paragraph", + "content": "The following conference videos are available:" + }, + { + "contentnewsType": "paragraph", + "content": "" + }, + { + "contentnewsType": "paragraph", + "content": "Please like or comment on the videos on the CVE Program Channel on YouTube." + } + ] + }, + { + "id": 676, + "newsType": "news", + "title": "Minutes from CVE Board Teleconference Meeting on April 29 Now Available", + "urlKeywords": "CVE Board Minutes from April 29", + "date": "2026-06-02", + "description": [ + { + "contentnewsType": "paragraph", + "content": "The CVE Board held a teleconference meeting on April 29, 2026. Read the meeting minutes summary." + }, + { + "contentnewsType": "paragraph", + "content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information." + } + ] + }, { "id": 675, "newsType": "news", @@ -320,7 +501,7 @@ }, { "contentnewsType": "paragraph", - "content": "" + "content": "" }, { "contentnewsType": "paragraph", @@ -865,7 +1046,7 @@ }, { "contentnewsType": "paragraph", - "content": "CNAs are vendor, researcher, open source, CERT, hosted service, and bug bounty provider organizations authorized by the CVE Program to assign CVE IDs to vulnerabilities and publish CVE Records within their own specific scopes of coverage." + "content": "CNAs are vendor, researcher, open source, CERT, hosted service, bug bounty provider, and consortium organizations authorized by the CVE Program to assign CVE IDs to vulnerabilities and publish CVE Records within their own specific scopes of coverage." }, { "contentnewsType": "paragraph", @@ -1250,7 +1431,7 @@ }, { "contentnewsType": "paragraph", - "content": "Resources mentioned in the podcast include:
" + "content": "Resources mentioned in the podcast include:
" }, { "contentnewsType": "paragraph", diff --git a/src/views/About/Metrics.vue b/src/views/About/Metrics.vue index a8f53f31..0c1b1304 100644 --- a/src/views/About/Metrics.vue +++ b/src/views/About/Metrics.vue @@ -334,14 +334,14 @@

CNA Enrichment Recognition List

-

Last Updated:
- Total CNAs: 261

+

Last Updated:
+ Total CNAs: 259

diff --git a/src/views/ResourcesSupport/Resources.vue b/src/views/ResourcesSupport/Resources.vue index ef7336f9..be876ee9 100644 --- a/src/views/ResourcesSupport/Resources.vue +++ b/src/views/ResourcesSupport/Resources.vue @@ -319,6 +319,11 @@ Videos: