GCVE

GCVE BCP-07 v3.0: From KEV to NKEV - No Known Exploitable Vulnerability (NKEV) assessments

#GCVE#BCP#KEV#CRA

We are pleased to announce the publication of GCVE BCP-07 version 3.0, extending the Known Exploited Vulnerability (KEV) Assertion Format with support for No Known Exploitable Vulnerability (NKEV) assessments.

Read more →

October 5, 2026

GCVE BCP-05-X-03: Bringing Vulnerability Handling Timelines into Vulnerability Records

#GCVE#BCP#CRA

The extension provides a structured and machine-readable way to represent the lifecycle of a vulnerability from discovery and reporting through acknowledgement, validation, remediation and public disclosure.

Read more →

October 1, 2026

GCVE at Vulnopticon 2026

#GCVE#Conference

We were very happy to participate in **Vulnopticon 2026** and to meet so many people interested in vulnerability identification, publication, coordination, and management.

Read more →

September 28, 2026

GCVE Workshop Before Vulnopticon 2026 – Slides and Materials

#GCVE#Workshop

On 22 September 2026, the GCVE community held a workshop in the context of Vulnopticon 2026. The workshop brought together discussions around decentralized vulnerability identification, Coordinated Vulnerability Disclosure (CVD), vulnerability data sovereignty, open-source tooling, automation, and the role of AI in the vulnerability ecosystem.

Read more →

September 23, 2026

GCVE BCP-07 Updated: A Directory for Known Exploited Vulnerability Catalogues

#GCVE#GNA#vulnerability-intelligence#open-source#KEV

GCVE BCP-07 Updated: A Directory for Known Exploited Vulnerability Catalogues

Read more →

September 1, 2026

GCVE recent activities: standards, software and a growing GNA community

#GCVE#GNA#vulnerability-intelligence#open-source#KEV#CPE#sightings

A review of GCVE activities from 26 May to 13 August 2026, including work on BCP-07, draft BCP-11 and BCP-12, Luxembourg–Québec cooperation, the GCVE Lab proposal, Vulnerability-Lookup 5.0, CPE.GCVE.EU and seven new GNAs.

Read more →

August 13, 2026

GCVE BCP-12: A Standard Sighting Format for Vulnerabilities

#GCVE#Sighting#CTI#vulnerability-management#open-source

a standard format for recording and exchanging vulnerability sightings

Read more →

August 1, 2026

Introducing CPE.GCVE.EU: A collaborative catalog for vendors, products, CPEs and PURLs

#GCVE#CPE#PURL#vulnerability-management#open-source

CPE.GCVE.EU provides a browsable, searchable and collaborative catalog of vendors, products, CPEs and their relationships with GCVE and PURL data.

Read more →

June 2, 2026

Vulnerability-Lookup 5.0 Released: Making Coordinated Vulnerability Disclosure Easier for GCVE GNAs

#announce#GCVE#GNA#vulnerability-lookup#CVD

The GCVE initiative is pleased to welcome the release of Vulnerability-Lookup 5.0.0, a major new version of the open-source software that powers db.gcve.eu. This release is especially important for the GCVE ecosystem: it introduces new capabilities that make it easier for GCVE Numbering Authorities (GNAs) to manage their vulnerability publication workflows and support a practical Coordinated Vulnerability Disclosure (CVD) process using open, interoperable tooling. Vulnerability-Lookup already plays a central role in the GCVE ecosystem. It provides the foundation for collecting, correlating, publishing, and synchronising vulnerability information across independent sources. With version 5.0, the project takes an important additional step: supporting GNAs not only as publishers of vulnerability records, but also throughout the operational process of reserving identifiers, preparing advisories, managing their state, and publishing structured information.

Read more →

May 29, 2026

GCVE recent activities: building a decentralised and operational vulnerability ecosystem

#GCVE#vulnerability-intelligence#open-source#KEV#CPE#AI

A review of GCVE activities and achievements from 25 February to 25 May 2026, including new and revised Best Current Practices, based on public GitHub work and official GCVE publications.

Read more →

May 25, 2026