Uploaded May 2026 | Updated September 2026, 1 hour ago
Art Manion (Tharros Labs, US), Lindsey Cerkovnik (CISA, US)
The CISA Vulnrichment project has demonstrated how a CVE Program authorized data publisher (ADP) can provide additional information to CVE Records, supporting a more consistent baseline that includes SSVC, KEV, CVSS, and CWE. Beyond this baseline, Vulnrichment allows CISA to experiment with different types of information, assessing costs, value to consumers, and potential policy recommendations. What additional information should Vulnrichment provide? Or stop providing? What if Vulnrichment disagrees with CNA-provided information? This presentation will review "Vulnrichment Year 2" and explore new enrichment options.
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure
(CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.
Art Manion (Tharros Labs, US), Lindsey Cerkovnik (CISA, US)
The CISA Vulnrichment project has demonstrated how a CVE Program authorized data publisher (ADP) can provide additional information to CVE Records, supporting a more consistent baseline that includes SSVC, KEV, CVSS, and CWE. Beyond this baseline, Vulnrichment allows CISA to experiment with different types of information, assessing costs, value to consumers, and potential policy recommendations. What additional information should Vulnrichment provide? Or stop providing? What if Vulnrichment disagrees with CNA-provided information? This presentation will review "Vulnrichment Year 2" and explore new enrichment options.
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure
(CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.










