Uploaded May 2026 | Updated September 2026, 5 hours ago
Art Manion (Tharros Labs, US), Jeremy Daigneau (MITRE, US), Lisa Olson (Microsoft, US), Yogesh Mittal (Red Hat, IN)
Software is made up of other software, and globally indentifying software and relationships between software components remains a hard problem. Work on Software Bill of Materials (SBOM) lead to Vulnerability Exploitabilty eXchange (VEX): Conveying how downstream software affected (or not) by a vulnerability in an upstream component. The CVE Program is running a Supplier authorized data publisher (SADP) pilot to help determine how best to collect, provide, and manage VEX-like inherited vulnerability status information. This panel will frame the goals, questions, and design of the SADP pilot (how it started) and discuss what the participants have learned up to this point (how it's going).
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Jeremy Daigneau is a Lead software engineer at MITRE. He began working at MITRE in 2015 and started working on the CVE Program as the lead developer of the CVE-Services API in early 2022. He’s since worked on many different CVE automation components. Jeremy is currently the CVE Automation team lead, which includes multiple different CVE automation applications, such as CVE-Services, CVE.org, CVE search, and more.
Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.
Yogesh Mittal is a PSIRT Manager at Red Hat, where he orchestrates strategic initiatives at the intersection of enterprise security and open source supply chain health. He oversaw Red Hat’s elevation to both CVE Program Root and CNA of Last Resort (CNA-LR) status. As a member of the CVE Program Roots Council, Yogesh plays a central role in evolving CNA Policy and operational standards, ensuring that governance frameworks are robust enough for global enterprises while remaining viable for decentralized communities.
Beyond policy, Yogesh bridges the gap between corporate governance and operational reality to align industry standards with the needs of the modern supply chain. He established a collaborative forum for Open Source CNAs and is dedicated to operationalizing "Federated Responsibility"—designing policy-backed frameworks that improve data quality without overburdening the volunteer workforce.
Art Manion (Tharros Labs, US), Jeremy Daigneau (MITRE, US), Lisa Olson (Microsoft, US), Yogesh Mittal (Red Hat, IN)
Software is made up of other software, and globally indentifying software and relationships between software components remains a hard problem. Work on Software Bill of Materials (SBOM) lead to Vulnerability Exploitabilty eXchange (VEX): Conveying how downstream software affected (or not) by a vulnerability in an upstream component. The CVE Program is running a Supplier authorized data publisher (SADP) pilot to help determine how best to collect, provide, and manage VEX-like inherited vulnerability status information. This panel will frame the goals, questions, and design of the SADP pilot (how it started) and discuss what the participants have learned up to this point (how it's going).
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Jeremy Daigneau is a Lead software engineer at MITRE. He began working at MITRE in 2015 and started working on the CVE Program as the lead developer of the CVE-Services API in early 2022. He’s since worked on many different CVE automation components. Jeremy is currently the CVE Automation team lead, which includes multiple different CVE automation applications, such as CVE-Services, CVE.org, CVE search, and more.
Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.
Yogesh Mittal is a PSIRT Manager at Red Hat, where he orchestrates strategic initiatives at the intersection of enterprise security and open source supply chain health. He oversaw Red Hat’s elevation to both CVE Program Root and CNA of Last Resort (CNA-LR) status. As a member of the CVE Program Roots Council, Yogesh plays a central role in evolving CNA Policy and operational standards, ensuring that governance frameworks are robust enough for global enterprises while remaining viable for decentralized communities.
Beyond policy, Yogesh bridges the gap between corporate governance and operational reality to align industry standards with the needs of the modern supply chain. He established a collaborative forum for Open Source CNAs and is dedicated to operationalizing "Federated Responsibility"—designing policy-backed frameworks that improve data quality without overburdening the volunteer workforce.










