The Vulnerability Identity Crisis @FIRSTdotorg
The Vulnerability Identity Crisis  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 3 hours ago
Art Manion (Tharros Labs, US), Jay Jacobs (Empirical Security, US)

Current vulnerability management programs struggle with identity. Anyone working in defensive vulnerability management will recognize the challenges in associating a vulnerability with the variety of products used in or by any technology estate. We struggle not only with product identification but also vulnerability identification. This double challenge of poor product and poor vulnerability identity creates a collection of vulnerability records that provide sub‑optimal coverage, cannot be de‑duplicated within and across vulnerability data sources, and require significant human resources to manage.

These records are often overly complicated or overly simplistic and difficult to associate with other critical information. This work is based on two long‑time vulnerability veterans spending the better part of a year discussing and debating the state of vulnerability‑information management and focusing on underlying first principles. The result is Minimum Viable Vulnerability Enumeration (MVVE) for every vulnerability record and a detailed ontology for defining and assessing the importance of other vulnerability‑information elements.

---

Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of ANALYGENCE Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).

Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS), a co-chair of the EPSS special interest group at FIRST and chair of the Consumer Working Group within the CVE program. He is also a co-founder of the Society for Information Risk Analysts (SIRA), a not-for-profit association dedicated to advancing risk management practices where he served on the board of directors for several years.
The Vulnerability Identity CrisisSpeeding Up Vulnerability Triage: Automating Context Retrieval with AI AgentsPanel: Tips and Tricks to Run a CSIRT in Low-income and Fragile ContextsEngaging with the Media to Foster Cybersecurity ResilienceEvading in Plain Sight: How Adversaries Beat User-Mode Protection EnginesVulnrichment PlaygroundBenchmarking Your Constituency: A Practical Framework for CERTs with Results from Academic SectorBillions of Indicators, Zero Action: How We Fixed ThatCritical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help Me
FIRST |

The Vulnerability Identity Crisis

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER