NATO Cyber Centre Joins CVE Numbering Network
CyberScoop reported that NATO’s cyber defence arm and AISLE joined the ENISA Root as CVE numbering authorities, adding new channels for tracking software flaws as AI changes vulnerability discovery.

NATO’s cyber defence arm and AI security startup AISLE have gained authority to issue CVE identifiers, CyberScoop reported, expanding Europe’s role in the system used to name and track publicly disclosed software flaws.
The change puts two very different organisations inside the ENISA Root for the Common Vulnerabilities and Exposures programme.
The NATO Cyber Security Centre can assign identifiers across the NATO enterprise, while AISLE’s mandate is limited to vulnerabilities discovered in its own products.
Vendors, researchers and government defenders gain a clearer label before flaws are shared, patched or discussed across separate organisations.
ENISA Root Adds NATO And AISLE
The European Union Agency for Cybersecurity announced the additions last week.
Twenty numbering authorities now sit under the ENISA Root: 12 brought in by ENISA itself and eight moved from the MITRE Root, the U.S. nonprofit-operated structure that has handled the programme’s daily work for more than 20 years.
The CVE system gives each public vulnerability a unique record.
That record becomes the common marker used by governments, suppliers and security teams when they refer to a specific flaw, reducing confusion when advisories, patches and incident reports cross organisational or national boundaries.
NATO’s new authority covers eligible flaws across alliance systems.
The NATO Cyber Security Centre guards NATO networks, monitors threats and coordinates responses when incidents occur, and the new role is designed to make tracking more consistent and allow information-sharing with trusted partners earlier in the process.
AI Discovery Raises The Numbering Burden
ENISA cybersecurity and operations chief Hans de Vries linked the expansion to shifts in the global threat landscape and to frontier AI models that can affect both flaw discovery and exploitation.
His statement framed ENISA’s role as part of a more globally representative and scalable identification ecosystem.
That AI context is central to the timing.
Automated discovery can increase the number of flaws that need triage, validation and public identifiers, while exploit-development capabilities shorten the window between discovery and operational risk.
A numbering authority does not itself fix a vulnerability, but it creates the shared reference point that lets defenders, vendors and coordinators move around the same record.
AISLE Gets A Narrower Mandate
AISLE’s authorisation is narrower than NATO’s.
The company, which has offices in San Francisco and Prague, said its CVE designation covers vulnerabilities found in its own products, so it can issue records directly instead of routing each request through an outside numbering authority.
Jaya Baloo, AISLE’s co-founder, called the step foundational and linked coordinated disclosure to holding the company’s products to the same standard it expects from others.
The company also credited its research team with hundreds of disclosures affecting widely used open-source projects including OpenSSL, Linux, Apache and OpenEMR, each handled through the relevant authority for that project.
CVE Governance Remains Unsettled
The expansion follows a period of pressure on vulnerability tracking.
The CVE programme narrowly avoided disruption in April 2025 when an 11-month contract extension prevented the shutdown of MITRE’s work.
Since then, European nonprofits and private entities have launched competing or complementary databases intended to coordinate how flaws are tracked, disclosed and patched.
One of those efforts is the Global CVE Allocation System, launched earlier this year by the Computer Incident Response Center Luxembourg.
A timetable for how ENISA-rooted assignments will operate alongside newer alternatives such as GCVE remains absent.




















