Uploaded August 2026 | Updated September 2026, 3 hours ago
Art Manion (Tharros Labs, US), Jay Jacobs (Empirical Security, US)
Current vulnerability management programs struggle with identity. Anyone working in defensive vulnerability management will recognize the challenges in associating a vulnerability with the variety of products used in or by any technology estate. We struggle not only with product identification but also vulnerability identification. This double challenge of poor product and poor vulnerability identity creates a collection of vulnerability records that provide sub‑optimal coverage, cannot be de‑duplicated within and across vulnerability data sources, and require significant human resources to manage.
These records are often overly complicated or overly simplistic and difficult to associate with other critical information. This work is based on two long‑time vulnerability veterans spending the better part of a year discussing and debating the state of vulnerability‑information management and focusing on underlying first principles. The result is Minimum Viable Vulnerability Enumeration (MVVE) for every vulnerability record and a detailed ontology for defining and assessing the importance of other vulnerability‑information elements.
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of ANALYGENCE Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS), a co-chair of the EPSS special interest group at FIRST and chair of the Consumer Working Group within the CVE program. He is also a co-founder of the Society for Information Risk Analysts (SIRA), a not-for-profit association dedicated to advancing risk management practices where he served on the board of directors for several years.
Art Manion (Tharros Labs, US), Jay Jacobs (Empirical Security, US)
Current vulnerability management programs struggle with identity. Anyone working in defensive vulnerability management will recognize the challenges in associating a vulnerability with the variety of products used in or by any technology estate. We struggle not only with product identification but also vulnerability identification. This double challenge of poor product and poor vulnerability identity creates a collection of vulnerability records that provide sub‑optimal coverage, cannot be de‑duplicated within and across vulnerability data sources, and require significant human resources to manage.
These records are often overly complicated or overly simplistic and difficult to associate with other critical information. This work is based on two long‑time vulnerability veterans spending the better part of a year discussing and debating the state of vulnerability‑information management and focusing on underlying first principles. The result is Minimum Viable Vulnerability Enumeration (MVVE) for every vulnerability record and a detailed ontology for defining and assessing the importance of other vulnerability‑information elements.
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of ANALYGENCE Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS), a co-chair of the EPSS special interest group at FIRST and chair of the Consumer Working Group within the CVE program. He is also a co-founder of the Society for Information Risk Analysts (SIRA), a not-for-profit association dedicated to advancing risk management practices where he served on the board of directors for several years.










