Skip to content

Commit a9ba630

Browse files
rrobergerlxdev
andauthored
2/3/26 release branch (#3838)
* #3836 Move 1 Board member to Other Past Contributors * #3835 "CNA Enrichment Recognition List" info for 2/2/26 * #3834 Add 1 new CNA * #3834 Update 4 CNA's info * #3837 Added context explanatory text to CNAs vs CNA-LRs section * CVERecord: fix on-page navigation to anchors --------- Co-authored-by: Roy Lane <rlane@mitre.org>
1 parent 4c19694 commit a9ba630

7 files changed

Lines changed: 190 additions & 70 deletions

File tree

src/assets/data/CNAsList.json

Lines changed: 92 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -13414,21 +13414,21 @@
1341413414
"CNA": {
1341513415
"isRoot": false,
1341613416
"root": {
13417-
"shortName": "n/a",
13418-
"organizationName": "n/a"
13417+
"shortName": "ENISA",
13418+
"organizationName": "EU Agency for Cybersecurity (ENISA)"
1341913419
},
13420-
"roles": [
13421-
{
13422-
"helpText": "",
13423-
"role": "CNA"
13424-
}
13420+
"type": [
13421+
"CERT"
1342513422
],
1342613423
"TLR": {
1342713424
"shortName": "mitre",
1342813425
"organizationName": "MITRE Corporation"
1342913426
},
13430-
"type": [
13431-
"CERT"
13427+
"roles": [
13428+
{
13429+
"helpText": "",
13430+
"role": "CNA"
13431+
}
1343213432
]
1343313433
},
1343413434
"country": "Slovak Republic"
@@ -16369,21 +16369,21 @@
1636916369
"CNA": {
1637016370
"isRoot": false,
1637116371
"root": {
16372-
"shortName": "n/a",
16373-
"organizationName": "n/a"
16372+
"shortName": "ENISA",
16373+
"organizationName": "EU Agency for Cybersecurity (ENISA)"
1637416374
},
16375-
"roles": [
16376-
{
16377-
"helpText": "",
16378-
"role": "CNA"
16379-
}
16375+
"type": [
16376+
"CERT"
1638016377
],
1638116378
"TLR": {
1638216379
"shortName": "mitre",
1638316380
"organizationName": "MITRE Corporation"
1638416381
},
16385-
"type": [
16386-
"CERT"
16382+
"roles": [
16383+
{
16384+
"helpText": "",
16385+
"role": "CNA"
16386+
}
1638716387
]
1638816388
},
1638916389
"country": "Finland"
@@ -17131,21 +17131,21 @@
1713117131
"CNA": {
1713217132
"isRoot": false,
1713317133
"root": {
17134-
"shortName": "n/a",
17135-
"organizationName": "n/a"
17134+
"shortName": "ENISA",
17135+
"organizationName": "EU Agency for Cybersecurity (ENISA)"
1713617136
},
17137-
"roles": [
17138-
{
17139-
"helpText": "",
17140-
"role": "CNA"
17141-
}
17137+
"type": [
17138+
"CERT"
1714217139
],
1714317140
"TLR": {
1714417141
"shortName": "mitre",
1714517142
"organizationName": "MITRE Corporation"
1714617143
},
17147-
"type": [
17148-
"CERT"
17144+
"roles": [
17145+
{
17146+
"helpText": "",
17147+
"role": "CNA"
17148+
}
1714917149
]
1715017150
},
1715117151
"country": "Poland"
@@ -27091,21 +27091,21 @@
2709127091
"CNA": {
2709227092
"isRoot": false,
2709327093
"root": {
27094-
"shortName": "n/a",
27095-
"organizationName": "n/a"
27094+
"shortName": "ENISA",
27095+
"organizationName": "EU Agency for Cybersecurity (ENISA)"
2709627096
},
27097-
"roles": [
27098-
{
27099-
"helpText": "",
27100-
"role": "CNA"
27101-
}
27097+
"type": [
27098+
"Bug Bounty Provider"
2710227099
],
2710327100
"TLR": {
2710427101
"shortName": "mitre",
2710527102
"organizationName": "MITRE Corporation"
2710627103
},
27107-
"type": [
27108-
"Bug Bounty Provider"
27104+
"roles": [
27105+
{
27106+
"helpText": "",
27107+
"role": "CNA"
27108+
}
2710927109
]
2711027110
},
2711127111
"country": "France"
@@ -28189,5 +28189,61 @@
2818928189
]
2819028190
},
2819128191
"country": "China"
28192+
},
28193+
{
28194+
"shortName": "CODRA",
28195+
"cnaID": "CNA-2026-0007",
28196+
"organizationName": "CODRA",
28197+
"scope": "CODRA’s products and related services.",
28198+
"contact": [
28199+
{
28200+
"email": [
28201+
{
28202+
"label": "Email",
28203+
"emailAddr": "secure.panorama@codra.net"
28204+
}
28205+
],
28206+
"contact": [],
28207+
"form": []
28208+
}
28209+
],
28210+
"disclosurePolicy": [
28211+
{
28212+
"label": "Policy",
28213+
"language": "",
28214+
"url": "https://my.codra.net/en-gb/messages/csirt-disclosure-policy"
28215+
}
28216+
],
28217+
"securityAdvisories": {
28218+
"alerts": [],
28219+
"advisories": [
28220+
{
28221+
"label": "Advisories",
28222+
"url": "https://my.codra.net/en-gb/csirt"
28223+
}
28224+
]
28225+
},
28226+
"resources": [],
28227+
"CNA": {
28228+
"isRoot": false,
28229+
"root": {
28230+
"shortName": "icscert",
28231+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)"
28232+
},
28233+
"type": [
28234+
"Vendor"
28235+
],
28236+
"TLR": {
28237+
"shortName": "CISA",
28238+
"organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)"
28239+
},
28240+
"roles": [
28241+
{
28242+
"helpText": "",
28243+
"role": "CNA"
28244+
}
28245+
]
28246+
},
28247+
"country": "France"
2819228248
}
2819328249
]

src/assets/data/currentBoardMembersList.json

Lines changed: 0 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -47,14 +47,6 @@
4747
"organizationURL": "https://uk.linkedin.com/in/infosecjen",
4848
"role": "Board"
4949
},
50-
{
51-
"familyName": "Emsweller",
52-
"firstName": "Patrick",
53-
"imageURL": "",
54-
"organization": "Cisco Systems, Inc.",
55-
"organizationURL": "https://www.cisco.com/",
56-
"role": "Board"
57-
},
5850
{
5951
"familyName": "Gazlay",
6052
"firstName": "Jay",

src/assets/data/metrics.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1176,7 +1176,7 @@
11761176
},
11771177
{
11781178
"month": "February",
1179-
"value": "TBA"
1179+
"value": "1"
11801180
},
11811181
{
11821182
"month": "March",

src/assets/data/news.json

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,66 @@
11
{
22
"currentNews": [
3+
{
4+
"id": 625,
5+
"newsType": "news",
6+
"title": "CODRA Added as CVE Numbering Authority (CNA)",
7+
"urlKeywords": "CODRA Added as CNA",
8+
"date": "2026-02-03",
9+
"description": [
10+
{
11+
"contentnewsType": "paragraph",
12+
"content": "<a href='/PartnerInformation/ListofPartners/partner/CODRA'>CODRA</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for CODRA’s products and related services."
13+
},
14+
{
15+
"contentnewsType": "paragraph",
16+
"content": "To date, <a href='/PartnerInformation/ListofPartners'>491 CNAs</a> (488 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>41 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. CODRA is the 9th CNA from France."
17+
},
18+
{
19+
"contentnewsType": "paragraph",
20+
"content": "CODRA’s Root is the <a href='/PartnerInformation/ListofPartners/partner/icscert'>CISA ICS Root</a>."
21+
}
22+
]
23+
},
24+
{
25+
"id": 624,
26+
"newsType": "blog",
27+
"title": "Vulnerability Data Enrichment for CVE Records: 256 CNAs on the Enrichment Recognition List for February 2, 2026",
28+
"urlKeywords": "CNA Enrichment Recognition List Update",
29+
"date": "2026-02-03",
30+
"author": {
31+
"name": "CVE Program",
32+
"organization": {
33+
"name": "CVE Program",
34+
"url": ""
35+
},
36+
"title": "",
37+
"bio": ""
38+
},
39+
"description": [
40+
{
41+
"contentnewsType": "image",
42+
"imageWidth": "",
43+
"href": "/news/CnaEnrichmentRecognitionList.png",
44+
"altText": "Increasing the Value of the CVE Record - CNA Enrichment Recognition List"
45+
},
46+
{
47+
"contentnewsType": "paragraph",
48+
"content": "The “<a href='/About/Metrics#CNAEnrichmentRecognition'>CNA Enrichment Recognition List</a>” for February 2, 2026, is now available with 256 CNAs listed. Published monthly on the CVE website, the list recognizes those <a href='/ProgramOrganization/CNAs'>CVE Numbering Authorities (CNAs)</a> that are actively providing enhanced vulnerability data in their <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a>. CNAs are added to the list if they provide <a href='https://www.first.org/cvss/' target='_blank'>Common Vulnerability Scoring System (CVSS)</a> and <a href='https://cwe.mitre.org/' target='_blank'>Common Weakness Enumeration (CWE&trade;)</a> in at least 98% of their records that were published within two weeks of their most recently published record."
49+
},
50+
{
51+
"contentnewsType": "paragraph",
52+
"content": "CNA Enrichment Recognition List criteria and reporting are intended to recognize those <a href='/ProgramOrganization/CNAs'>CNAs</a> taking on the work to increase the value of <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for downstream consumers, and encourage others to do the same. Enrichment Recognition List criteria may change over time. The most recent modifications occurred in June 2025 when data pulls were moved from every two weeks and based upon data from the last 12 months, to the current reporting of once-per-month data pulls based upon data from the previous six months."
53+
},
54+
{
55+
"contentnewsType": "paragraph",
56+
"content": "For more about the recognition list, see “<a href='/Media/News/item/blog/2024/09/10/CNA-Enrichment-Recognition-List'>Recognition for CNAs Actively Providing Vulnerability Data Enrichment for CVE Records</a>.” To learn more about vulnerability information types like CVSS and CWE, see the <a href='/CVERecord/UserGuide'>CVE Record User Guide</a>. View the most current CNA Enrichment Recognition List on the CVE website Metrics page <a href='/About/Metrics#CNAEnrichmentRecognition'>here</a>."
57+
},
58+
{
59+
"contentnewsType": "paragraph",
60+
"content": "CNA Enrichment Recognition List for February 2, 2026, with 256 CNAs listed: <ul><li>Acronis International GmbH</li><li>Adobe Systems Incorporated</li><li>Advanced Micro Devices Inc.</li><li>Airbus</li><li>AlgoSec</li><li>Altera</li><li>Altium</li><li>Amazon</li><li>AMI</li><li>ARC Informatique</li><li>Arista Networks, Inc.</li><li>Armis, Inc.</li><li>Asea Brown Boveri Ltd.</li><li>ASR Microelectronics Co., Ltd.</li><li>ASUSTeK Computer Incorporation</li><li>ASUSTOR Inc.</li><li>ATISoluciones Diseño de Sistemas Electrónicos, S.L.</li><li>Austin Hackers Anonymous</li><li>Autodesk</li><li>Automotive Security Research Group (ASRG)</li><li>Axis Communications AB</li><li>AxxonSoft Limited</li><li>Azure Access Technology</li><li>Bitdefender</li><li>Bizerba SE & Co. KG</li><li>Black Duck Software, Inc.</li><li>Black Lantern Security</li><li>BlackBerry</li><li>Bugcrowd Inc.</li><li>CA Technologies</li><li>Canon EMEA</li><li>Canon Inc.</li><li>Canonical Ltd.</li><li>Carrier Global Corporation</li><li>Centreon</li><li>CERT.PL</li><li>CERT@VDE</li><li>Check Point Software Technologies Ltd.</li><li>Checkmarx</li><li>Checkmk GmbH</li><li>Cisco Systems, Inc.</li><li>Citrix Systems, Inc.</li><li>Cloudflare, Inc.</li><li>Commvault Systems Inc</li><li>Concrete CMS</li><li>ConnectWise LLC</li><li>Crestron Electronics, Inc.</li><li>CrowdStrike Holdings, Inc.</li><li>CyberArk Labs</li><li>CyberDanube</li><li>Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government</li><li>Dahua Technologies</li><li>Danfoss</li><li>Dassault Systèmes</li><li>Delinea, Inc.</li><li>Dell EMC</li><li>Delta Electronics, Inc.</li><li>Digi International Inc.</li><li>Docker Inc.</li><li>dotCMS LLC</li><li>Dragos, Inc.</li><li>Eaton</li><li>Eclipse Foundation</li><li>Elastic</li><li>EnterpriseDB Corporation</li><li>Environmental Systems Research Institute, Inc. (Esri)</li><li>Ericsson</li><li>Erlang Ecosystem Foundation</li><li>ESET, spol. s r.o.</li><li>EU Agency for Cybersecurity (ENISA)</li><li>Extreme Networks, Inc.</li><li>F5 Networks</li><li>Fedora Project (Infrastructure Software)</li><li>Fermax Technologies SLU</li><li>Financial Security Institute (FSI)</li><li>Flexera Software LLC</li><li>floragunn GmbH</li><li>Fluid Attacks</li><li>Fortinet, Inc.</li><li>Fortra, LLC</li><li>Foxit Software Incorporated</li><li>Gallagher Group Ltd</li><li>GE Vernova</li><li>Genetec Inc.</li><li>GitHub (maintainer security advisories)</li><li>GitHub Inc, (Products Only)</li><li>GitLab Inc.</li><li>Glyph & Cog, LLC</li><li>Google Cloud</li><li>Google LLC</li><li>Gridware Cybersecurity</li><li>Hallo Welt! GmbH</li><li>Hanwha Vision Co., Ltd.</li><li>Harborist</li><li>HashiCorp Inc.</li><li>HeroDevs</li><li>HiddenLayer, Inc.</li><li>Hitachi Energy</li><li>Hitachi Vantara</li><li>Hitachi, Ltd.</li><li>Honeywell International Inc.</li><li>Honor Device Co., Ltd.</li><li>HP Inc.</li><li>HYPR Corp</li><li>IBM Corporation</li><li>ICS-CERT</li><li>Indian Computer Emergency Response Team (CERT-In)</li><li>Insyde Software</li><li>Intel Corporation</li><li>Internet Systems Consortium (ISC)</li><li>Israel National Cyber Directorate</li><li>Ivanti</li><li>Jamf</li><li>Jaspersoft</li><li>JetBrains s.r.o.</li><li>JFROG</li><li>Johnson Controls</li><li>JPCERT/CC</li><li>Juniper Networks, Inc.</li><li>Kaspersky</li><li>KNIME AG</li><li>KrCERT/CC</li><li>Kubernetes</li><li>Larry Cashdollar</li><li>Legion of the Bouncy Castle Inc.</li><li>Lenovo Group Ltd.</li><li>Lexmark International Inc.</li><li>LG Electronics</li><li>Liferay, Inc.</li><li>M-Files Corporation</li><li>Maritime Hacking Village</li><li>Mattermost, Inc</li><li>Mautic</li><li>Medtronic</li><li>Microchip Technology</li><li>Microsoft Corporation</li><li>Milestone Systems A/S</li><li>Mitsubishi Electric Corporation</li><li>Monash University - Cyber Security Incident Response Team</li><li>Moxa Inc.</li><li>N-able</li><li>National Cyber Security Centre Finland</li><li>National Instruments</li><li>NEC Corporation</li><li>Neo4j</li><li>NETGEAR</li><li>Netskope</li><li>NLnet Labs</li><li>NortonLifeLock Inc</li><li>Nozomi Networks Inc.</li><li>Nvidia Corporation</li><li>Omnissa, LLC</li><li>OMRON Corporation</li><li>ONEKEY GmbH</li><li>Open Design Alliance</li><li>Open-Xchange</li><li>OpenHarmony</li><li>OpenJS Foundation</li><li>OpenText (formerly Micro Focus)</li><li>OpenVPN Inc.</li><li>OPPO</li><li>Palantir Technologies</li><li>Palo Alto Networks</li><li>Panasonic Holdings Corporation</li><li>PaperCut Software Pty Ltd</li><li>Pegasystems</li><li>PHP Group</li><li>Ping Identity Corporation</li><li>Progress Software Corporation</li><li>Proofpoint Inc.</li><li>Protect AI</li><li>Pure Storage, Inc.</li><li>QNAP Systems, Inc.</li><li>Qualcomm, Inc.</li><li>Qualys, Inc.</li><li>Radiometer Medical ApS</li><li>rami.io GmbH</li><li>Rapid7, Inc.</li><li>Real-Time Innovations, Inc.</li><li>Red Hat CNA-LR</li><li>Red Hat, Inc.</li><li>Ribose Limited</li><li>Robert Bosch GmbH</li><li>Roche Diagnostics</li><li>Rockwell Automation</li><li>S21sec Cyber Solutions by Thales</li><li>SailPoint Technologies</li><li>SAP SE</li><li>Schneider Electric SE</li><li>Seagate Technology</li><li>Security Risk Advisors</li><li>ServiceNow</li><li>SICK AG</li><li>Siemens</li><li>Silicon Labs</li><li>Snyk</li><li>Softing</li><li>SoftIron</li><li>SolarWinds</li><li>Solidigm</li><li>Sonatype Inc.</li><li>Sophos</li><li>StrongDM</li><li>Super Micro Computer, Inc.</li><li>Suse</li><li>Switzerland National Cyber Security Centre (NCSC)</li><li>Symantec - A Division of Broadcom</li><li>Synaptics</li><li>Synology Inc.</li><li>Talos</li><li>Tanium Inc.</li><li>TeamViewer Germany GmbH</li><li>Temporal Technologies Inc.</li><li>Tenable Network Security, Inc.</li><li>Teradyne Robotics</li><li>Thales Group</li><li>The Browser Company of New York</li><li>The Document Foundation</li><li>The Joomla! Project</li><li>The Missing Link Australia (TML)</li><li>The Qt Company</li><li>The Rust Project</li><li>The Tcpdump Group</li><li>The Wikimedia Foundation</li><li>TianoCore.org</li><li>TIBCO Software Inc.</li><li>Toreon</li><li>TP-Link Systems Inc.</li><li>TR-CERT (Computer Emergency Response Team of the Republic of Turkey)</li><li>Trend Micro, Inc.</li><li>TWCERT/CC</li><li>TYPO3 Association</li><li>upKeeper Solutions</li><li>Vaadin Ltd.</li><li>VMware</li><li>VulDB</li><li>VulnCheck</li><li>WatchGuard Technologies, Inc.</li><li>Western Digital</li><li>Wind River Systems Inc.</li><li>Wiz, Inc.</li><li>wolfSSL Inc.</li><li>Wordfence</li><li>WSO2 LLC</li><li>Xerox Corporation</li><li>Yandex N.V.</li><li>Yugabyte, Inc.</li><li>Zabbix</li><li>Zephyr Project</li><li>Zero Day Initiative</li><li>Zohocorp</li><li>Zoom Video Communications, Inc.</li><li>Zscaler, Inc.</li><li>ZTE Corporation</li><li>ZUSO Advanced Research Team (ZUSO ART)</li><li>Zyxel Corporation</li></ul>"
61+
}
62+
]
63+
},
364
{
465
"id": 623,
566
"newsType": "news",

0 commit comments

Comments
 (0)