Uploaded May 2026 | Updated September 2026, 46 minutes ago
Alec Summers (The MITRE Corporation, US), Yogesh Mittal (Red Hat, IN), Lisa Olson (Microsoft, US), Lindsey Cerkovnik (CISA, US), Jimmy Calderon (TrendAI)
Disagreements about vulnerabilities are inevitable in a globally scaled, federated ecosystem like CVE. In practice, CVE Record disputes occur for a variety of reasons, and when a dispute arises, the CVE Program’s “Policy and Procedure for Disputing a CVE Record” is followed. This can mean a CVE Record is updated to include different positions on an issue. Each side’s rationale is documented, and the record itself is explicitly tagged as “disputed.” Unless there is a convergence of perspective, the record may remain in this state indefinitely. This moderated panel brings together representatives from across the vulnerability ecosystem – including a supplier CNA, a CVE Root authority, a government stakeholder, a security researcher, and enterprise CVE data consumers – to examine how disputes arise, how they are handled today under the CVE Program dispute policy, and where that policy succeeds or falls short and needs to evolve. Rather than litigating individual cases, the panel uses the current CVE dispute policy as a shared reference point to explore how good-faith disagreement is navigated in practice, how revisions and updates propagate downstream, and how dispute mechanisms might evolve to deliver greater value to producers, consumers, and regulators alike. Attendees will leave with a more informed understanding of CVE Record dispute handling and greater insight into how policy, process, and transparency intersect in the CVE Program.
---
Alec Summers is a principal cybersecurity engineer at the MITRE Corporation with diverse and extensive experience in software assurance and vulnerability management, as well as cyber operations, assessments, and supply chain risk management. He is the MITRE CVE and CWE Project Leader, managing teams that support vulnerability and weakness research & analysis, content production, program coordination, services development, and community engagement across a global partner base comprising industry, government, and academia. He serves as the moderator for the CVE Board and CWE Board. LinkedIn: linkedin.com/in/ajrsummers
Yogesh Mittal is a PSIRT Manager at Red Hat, where he orchestrates strategic initiatives at the intersection of enterprise security and open source supply chain health. He oversaw Red Hat’s elevation to both CVE Program Root and CNA of Last Resort (CNA-LR) status. As a member of the CVE Program Roots Council, Yogesh plays a central role in evolving CNA Policy and operational standards, ensuring that governance frameworks are robust enough for global enterprises while remaining viable for decentralized communities. Beyond policy, Yogesh bridges the gap between corporate governance and operational reality to align industry standards with the needs of the modern supply chain. He established a collaborative forum for Open Source CNAs and is dedicated to operationalizing "Federated Responsibility"—designing policy-backed frameworks that improve data quality without overburdening the volunteer workforce.
Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.
Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.
Jimmy Calderon is a Senior Manager of Program Management at TrendAI Zero Day Initiative (ZDI), where he focuses on vulnerability acquisition, coordinated disclosure, and engagement within the offensive research community. He manages ZDI’s CNA program, including CVE assignments and dispute handling, and drives research efforts such as Pwn2Own, along with targeted research campaigns and partnerships with enterprise technology providers. Jimmy focuses on bridging the gap between vulnerability researchers and vendors, enabling discoveries to become effective, actionable protections across industry verticals throughout the broader security ecosystem.
Alec Summers (The MITRE Corporation, US), Yogesh Mittal (Red Hat, IN), Lisa Olson (Microsoft, US), Lindsey Cerkovnik (CISA, US), Jimmy Calderon (TrendAI)
Disagreements about vulnerabilities are inevitable in a globally scaled, federated ecosystem like CVE. In practice, CVE Record disputes occur for a variety of reasons, and when a dispute arises, the CVE Program’s “Policy and Procedure for Disputing a CVE Record” is followed. This can mean a CVE Record is updated to include different positions on an issue. Each side’s rationale is documented, and the record itself is explicitly tagged as “disputed.” Unless there is a convergence of perspective, the record may remain in this state indefinitely. This moderated panel brings together representatives from across the vulnerability ecosystem – including a supplier CNA, a CVE Root authority, a government stakeholder, a security researcher, and enterprise CVE data consumers – to examine how disputes arise, how they are handled today under the CVE Program dispute policy, and where that policy succeeds or falls short and needs to evolve. Rather than litigating individual cases, the panel uses the current CVE dispute policy as a shared reference point to explore how good-faith disagreement is navigated in practice, how revisions and updates propagate downstream, and how dispute mechanisms might evolve to deliver greater value to producers, consumers, and regulators alike. Attendees will leave with a more informed understanding of CVE Record dispute handling and greater insight into how policy, process, and transparency intersect in the CVE Program.
---
Alec Summers is a principal cybersecurity engineer at the MITRE Corporation with diverse and extensive experience in software assurance and vulnerability management, as well as cyber operations, assessments, and supply chain risk management. He is the MITRE CVE and CWE Project Leader, managing teams that support vulnerability and weakness research & analysis, content production, program coordination, services development, and community engagement across a global partner base comprising industry, government, and academia. He serves as the moderator for the CVE Board and CWE Board. LinkedIn: linkedin.com/in/ajrsummers
Yogesh Mittal is a PSIRT Manager at Red Hat, where he orchestrates strategic initiatives at the intersection of enterprise security and open source supply chain health. He oversaw Red Hat’s elevation to both CVE Program Root and CNA of Last Resort (CNA-LR) status. As a member of the CVE Program Roots Council, Yogesh plays a central role in evolving CNA Policy and operational standards, ensuring that governance frameworks are robust enough for global enterprises while remaining viable for decentralized communities. Beyond policy, Yogesh bridges the gap between corporate governance and operational reality to align industry standards with the needs of the modern supply chain. He established a collaborative forum for Open Source CNAs and is dedicated to operationalizing "Federated Responsibility"—designing policy-backed frameworks that improve data quality without overburdening the volunteer workforce.
Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.
Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.
Jimmy Calderon is a Senior Manager of Program Management at TrendAI Zero Day Initiative (ZDI), where he focuses on vulnerability acquisition, coordinated disclosure, and engagement within the offensive research community. He manages ZDI’s CNA program, including CVE assignments and dispute handling, and drives research efforts such as Pwn2Own, along with targeted research campaigns and partnerships with enterprise technology providers. Jimmy focuses on bridging the gap between vulnerability researchers and vendors, enabling discoveries to become effective, actionable protections across industry verticals throughout the broader security ecosystem.