MITRE announced on April 15 that their CVE contract ends on April 16. That timing alone raises some questions.
The language in the message feels very deliberate: āWeāre committed,ā āconsiderable efforts,ā āif a break were to occurā ā while they know a break will happen the next day. Thatās not just unfortunate timing. It looks like controlled messaging, maybe even a pressure move.
CVE isnāt some massive budget item. Itās a lightweight system with probably a small core team and some automation. Iād guess a handful of full-time staff, not dozens. So cutting this - of all things - doesnāt really look like cost-saving.
If the goal was to send a message about funding or contract uncertainty, they picked the most visible and disruptive program. And it worked ā everyoneās paying attention.
Itās worth noting that MITRE owns the CVE and CWE trademarks. Even if someone else takes over, theyāll still be operating within MITREās legal boundaries.
All in all, this looks less like a necessary budget cut and more like a strategic decision to generate visibility and urgency. Hard to read it any other way.
BREAKING.
From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.