As “Machine Speed” Discovery Looms, CISA Issues Guidance on Vulnerability Disclosure Programs
July 23, 2026
Vulnerability disclosure programs remain a blind spot for too many organizations—and frontier AI could soon make vulnerability discovery far easier and more frequent. New CISA and NSA guidance outlines practical steps for building effective coordinated vulnerability disclosure programs.
Vulnerability disclosure programs are something that have fallen through the cracks for a concerning amount of organizations. It is also an area where labor needs are expected to soon spike as frontier AI makes vulnerability discovery trivial. Through that lens, CISA (in partnership with the NSA) has issued new guidance that apprises organizations of their options and offers helpful suggestions for establishing best practices for coordinated vulnerability disclosure (CVD) programs.
The “Cybersecurity Information Sheet” is worthwhile reading for all, but especially those programs that are still at a developing level of maturity and may not yet have clear communications and policies in place for researchers seeking to report issues. This includes an overview of third-party assistance options, including aid available from the government and CISA itself.
New guidance offers aid as vulnerability disclosure preparedness becomes critical
The guidance is not just for those that are establishing new vulnerability disclosure programs; in fact, it strongly encourages regular review to ensure organizational familiarity with current best practices and that smooth channels of communication with researchers have been established.
It also notes that third-party options are available to those that are struggling to fully address vulnerability disclosure in-house. This includes incident response, bug bounty programs, filing of CVE numbers and outside security assessments among other items. CISA itself provides certain tools, such as the Common Security Advisory Framework (CSAF) and Vulnerability Exploitability eXchange (VEX), as well as free assessment and penetration testing options.
Can vulnerability disclosure keep pace with machine speed?
The hard truth is that many organizations are way behind on vulnerability disclosure, and there is precious little time to catch up while staring down the barrel of Mythos-tier AI becoming broadly available. At minimum this guidance helps organizations get oriented on the basics such as handling communications with independent researchers and setting terms for and limitations on their operations on company networks. For example, how should researchers structure their write-ups and present their proofs of concept? And even more fundamentally, how are they getting information on reporting procedures and points of contact? Are these things readily discoverable on an open public website? And are bug bounties offered?
One issue in this area that the guidance highlights is researcher concern about being slapped with “anti-hacking” laws when attempting to report in good faith. Researchers would also like clarity about whether or not (and to what extent) they will be credited when a vulnerability disclosure takes place, and what kind of embargo period can be expected.
Organizations still developing their vulnerability disclosure programs have a lot of decisions to face. Should they apply to become a CVE Numbering Authority and handle number assignment themselves, or contract the services of a third party? Are disclosures going to be packaged with other media materials, such as social media and blog posts or customer mailers? What exactly will researchers be authorized to do on the network, and will they be offered bounties or compensation?
While vulnerability discovery has to date tended to be infrequent enough to allow for even some of the world’s largest organizations to ignore some of these elements, the reality of the near future is small armies of both researchers and attackers regularly probing for weaknesses. As the guidance notes, it makes sense to allow researchers to be helpful in this area and open up an accessible path for them.



