GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference
We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference.
The workshop is free and open to everyone, but registration is required.
![]()
About the workshop
The workshop will provide an introduction to the GCVE initiative and its approach to improving and decentralising vulnerability identification, coordination, publication, and exploitation tracking.
A particular focus will be placed on how GCVE can support organisations involved in Coordinated Vulnerability Disclosure (CVD) processes, including vendors, open-source projects, vulnerability researchers, CSIRTs/CERTs, CNAs, and other vulnerability coordination actors.
We will also discuss how these processes can support evolving regulatory and operational requirements, including vulnerability disclosure activities related to the EU Cyber Resilience Act (CRA).
Topics
The workshop will cover:
- An overview of the GCVE initiative, its objectives, governance, and decentralised model.
- How organisations can use GCVE identifiers and become part of the GCVE ecosystem.
- Practical approaches to Coordinated Vulnerability Disclosure (CVD).
- Supporting vulnerability disclosure across different scopes, including vendors, open-source software, CSIRTs and regulatory contexts such as the CRA.
- The GCVE Best Current Practices (BCPs) and how they can be used to structure vulnerability disclosure and publication processes.
- GCVE tooling for vulnerability allocation, publication, synchronisation and distribution.
- Integration with Vulnerability-Lookup and related open-source tools.
- Approaches for publishing vulnerability advisories, tracking known exploited vulnerabilities, and sharing vulnerability-related information in a decentralised ecosystem.
- Open discussion with participants about existing CVD workflows, challenges and potential improvements.
The objective is to make the session practical: participants should leave with a better understanding of how GCVE and its associated tooling can help establish, simplify, or extend their own vulnerability disclosure processes.
Practical information
Date: 22 September 2026
Time: 14:00–18:00
Location: CIRCL/LHC offices, Luxembourg - CIRCL - Computer Incident Response Center Luxembourg c/o “Luxembourg House of Cybersecurity” g.i.e. 122, rue Adolphe Fischer L-1521 Luxembourg Grand-Duchy of Luxembourg
Participation: Free of charge — registration required
Related event: VulnOpticon
The workshop is intended for anyone involved or interested in vulnerability discovery, coordination, disclosure, vulnerability management, open-source security, CSIRT activities, or vulnerability policy.
We look forward to discussing practical vulnerability disclosure workflows and the future of the GCVE ecosystem with the community.