CVE Program submissions close July 9
- The CVE Program said July 9 is the deadline for topic submissions to its July 30 virtual conference on AI-enabled vulnerability discovery. - The key detail is the cutoff: 5 p.m. EDT on July 9, according to the CVE Program’s reminder on its official X account. - The next milestone is the July 30 virtual event, with details and related background posted on CVE.org.
The CVE Program said topic submissions for its July 30 virtual conference on AI-enabled vulnerability discovery close at 5 p.m. EDT on Wednesday, July 9, according to a reminder posted on the program’s official X account. The event is part of a broader CVE Program effort to gather input on how artificial intelligence is changing vulnerability discovery and the handling of CVE records. CVE.org lists the conference as a July 30, 2026 virtual community event and says the program is seeking “first-hand observations, discussion topics, and participants” from across the vulnerability ecosystem. ### What exactly closes on July 9? The July 9 deadline applies to topic submissions for the conference, not to general awareness of the event. The CVE Program’s June 30 notice on CVE.org described the session as a call for topics for a virtual conference scheduled for July 30, 2026. CVE.org’s news page lists that call under the headline “Call for Topics for ‘CVE and AI Vulnerability Discovery’ Virtual Conference on July 30, 2026.” (cve.org) The CVE Program said it wants input from researchers, software manufacturers, open-source maintainers, bug bounty operators, CVE Numbering Authorities, Roots, tooling vendors and downstream CVE data consumers. That framing indicates the program is looking beyond vulnerability discovery itself to the systems that assign, publish, enrich and consume CVE information. (cve.org) ### Why is the CVE Program focusing this event on AI? The CVE Program said on June 15 that it is opening a “structured community discussion” about how AI-enabled vulnerability discovery is affecting both the CVE Program and the broader vulnerability management ecosystem. The program said AI-enabled discovery is changing not only how flaws are found, but also how vulnerability information is reported, validated, coordinated, remediated, published, enriched, consumed and acted upon. (cve.org) The June 15 post said the central question is how CVE can continue to serve as a “trusted and scalable foundation” for vulnerability identification as the ecosystem adapts to greater speed, volume, uncertainty and AI-assisted consumption. The same post said the July 30 forum is meant to help frame those issues and invite wider community input. (cve.org) ### Is this a new issue for CVE, or part of a longer process? A February 18, 2025 CVE Program blog said the conference discussion builds on earlier work by the CVE AI Working Group. That post said the working group was established to assess how growing AI adoption could affect CVE assignment and record publication, and it described the effort as part of a still “pre-decisional journey.” (cve.org) The 2025 post also said some CVE Numbering Authorities were already encountering basic classification questions when AI is involved, including what product is affected and whether a vulnerability exists in a CVE sense. The program said those questions matter because many CVE consumers rely on CVE records for usable product information when checking whether a disclosed issue affects assets in their environments. (cve.org) ### Who is the CVE Program asking to participate? The June 15 CVE.org post names a broad set of participants: researchers, vendors, open-source maintainers, bug bounty operators, CNAs, Roots, tooling vendors and downstream data consumers. That list suggests the conference is aimed at the operational chain around CVEs, from discovery and assignment through enrichment and defender use. (cve.org) CVE.org describes itself as providing the authoritative reference method for publicly known information-security vulnerabilities and exposures. The program’s recent news feed also shows ongoing governance and ecosystem activity, including new CVE Numbering Authorities and board appointments in late June and early July. ### Where can readers track the next step after the deadline? (cve.org) The next dated milestone is July 30, 2026, when the virtual conference is scheduled to take place. CVE.org’s June 15 discussion post says registration details are provided there, and the site’s news page lists the call for topics alongside other current program updates. (cve.org) The immediate cutoff remains 5 p.m. EDT on July 9 for topic submissions, according to the program’s X reminder. After that, the public reference point is the July 30 event page and related CVE.org background posts on AI-related vulnerabilities and CVE record handling. (cve.org)