Uploaded May 2026 | Updated September 2026, 1 hour ago
Alec Summers (The MITRE Corporation, US), Steve Christey Coley (The MITRE Corporation, US)
In 2024, at the first VulnCon, I presented the CWE Program’s current state and road ahead, focusing on federation, community working groups, and infrastructure modernization as necessary foundations for growth. Two years later, it is now possible to reflect on what those investments enabled – and what has changed as a result. This session looks back on the last several years of CWE evolution to assess progress in usability, adoption, and practical application. In particular, it highlights measurable increases in root cause weakness mapping at the time of vulnerability disclosure, driven by clearer guidance, improved tooling, and sustained community collaboration. These changes have begun to transform CWE from a reference taxonomy into a usable signal for understanding systemic security failures. The talk also looks forward, arguing that the ecosystem is now positioned to move beyond reactive vulnerability and attack-centric thinking. If we want to avoid whole classes of vulnerabilities rather than keep responding to similar issues, we must increasingly frame security problems in terms of weaknesses – the conditions that make exploitation possible. By reflecting on how far the CWE community has come since 2024, this session explores what lies ahead and how shared language, measurement, and intent can drive more preventative outcomes.
---
Alec Summers is a principal cybersecurity engineer at the MITRE Corporation with diverse and extensive experience in software assurance and vulnerability management, as well as cyber operations, assessments, and supply chain risk management. He is the MITRE CVE and CWE Project Leader, managing teams that support vulnerability and weakness research & analysis, content production, program coordination, services development, and community engagement across a global partner base comprising industry, government, and academia. He serves as the moderator for the CVE Board and CWE Board. LinkedIn: linkedin.com/in/ajrsummers
Steve Christey Coley is a Principal INFOSEC Engineer at The MITRE Corporation. He was the co-founder and technical lead of CVE, and chair of its Editorial Board from 1999 to 2015. He co-authored the "Responsible Vulnerability Disclosure Process" IETF draft and contributed to CVSS v2. He is the co-founder and technical lead for the Common Weakness Enumeration (CWE) circa 2005. Since 2014, he has supported FDA in various aspects of medical device security, including vulnerability handling, risk assessment, threat modeling, SBOM handling, adoption of emerging technologies, and a rubric for applying CVSS to medical devices.
Alec Summers (The MITRE Corporation, US), Steve Christey Coley (The MITRE Corporation, US)
In 2024, at the first VulnCon, I presented the CWE Program’s current state and road ahead, focusing on federation, community working groups, and infrastructure modernization as necessary foundations for growth. Two years later, it is now possible to reflect on what those investments enabled – and what has changed as a result. This session looks back on the last several years of CWE evolution to assess progress in usability, adoption, and practical application. In particular, it highlights measurable increases in root cause weakness mapping at the time of vulnerability disclosure, driven by clearer guidance, improved tooling, and sustained community collaboration. These changes have begun to transform CWE from a reference taxonomy into a usable signal for understanding systemic security failures. The talk also looks forward, arguing that the ecosystem is now positioned to move beyond reactive vulnerability and attack-centric thinking. If we want to avoid whole classes of vulnerabilities rather than keep responding to similar issues, we must increasingly frame security problems in terms of weaknesses – the conditions that make exploitation possible. By reflecting on how far the CWE community has come since 2024, this session explores what lies ahead and how shared language, measurement, and intent can drive more preventative outcomes.
---
Alec Summers is a principal cybersecurity engineer at the MITRE Corporation with diverse and extensive experience in software assurance and vulnerability management, as well as cyber operations, assessments, and supply chain risk management. He is the MITRE CVE and CWE Project Leader, managing teams that support vulnerability and weakness research & analysis, content production, program coordination, services development, and community engagement across a global partner base comprising industry, government, and academia. He serves as the moderator for the CVE Board and CWE Board. LinkedIn: linkedin.com/in/ajrsummers
Steve Christey Coley is a Principal INFOSEC Engineer at The MITRE Corporation. He was the co-founder and technical lead of CVE, and chair of its Editorial Board from 1999 to 2015. He co-authored the "Responsible Vulnerability Disclosure Process" IETF draft and contributed to CVSS v2. He is the co-founder and technical lead for the Common Weakness Enumeration (CWE) circa 2005. Since 2014, he has supported FDA in various aspects of medical device security, including vulnerability handling, risk assessment, threat modeling, SBOM handling, adoption of emerging technologies, and a rubric for applying CVSS to medical devices.










