CVE Program Faces Shutdown After DHS Fails to Renew Contract – Security Flaw Tracking in Limbo
The CVE contract with MITRE wasn't renewed, threatening the global vulnerability tracking system.

The Common Vulnerabilities and Exposures (CVE) program, the de facto dictionary for security flaws used by developers worldwide, is teetering on the edge of collapse. The U.S. Department of Homeland Security (DHS) did not renew MITRE's contract to administer the program, and funding ceased on April 16, 2025.
For now, MITRE is keeping the lights on at its own expense, but that's not sustainable. If a solution isn't found soon, thousands of new vulnerabilities will go without identifiers, seriously hampering security professionals and developers who rely on CVE for patching and risk assessment.
What This Means for the IT Community
- Without CVE, coordination between vendors and researchers slows down.
- The risk of missing a critical vulnerability in your stack increases.
- Alternative databases may emerge, leading to fragmentation and confusion.
DHS remains silent, and the community is left guessing who will step in. Last year, a similar crisis hit the Known Exploited Vulnerabilities (KEV) catalog, but the contract was renewed at the eleventh hour.
METABYTE Studio's take: Moments like these remind us how fragile global IT infrastructure can be. We advise our clients not to rely on a single source of vulnerability data—diversify your monitoring and automate checks so that even if external services falter, your product stays secure.
NEXT STEP
Liked the approach?
We apply the same principles to client projects: AI, automation, products that don't die after launch.