CISA Moves Vulnerability Reports to VINCE-NT
CISA has shifted its vulnerability reporting and coordination work onto a revamped, agency-managed platform called VINCE-NT.
Vulnerability reporters, product suppliers and government case managers all pass through the same pipeline when a flaw gets disclosed to the US government. That pipeline has just changed hands and names. According to Infosecurity Magazine, the Cybersecurity and Infrastructure Security Agency has moved its vulnerability reporting and coordination work onto a new platform, retiring the version of the tool it had relied on since 2020.
The Platform Behind the Switch
Since 2020, CISA had been using the Vulnerability Information and Coordination Environment, known as VINCE. That platform was built the same year by the Computer Emergency and Response Team Coordination Center, a unit of Carnegie Mellon University's Software Engineering Institute.
From September 17, 2026, the agency is now using VINCE – New Technology, or VINCE-NT. The transition was announced by CISA in a social media post published on September 17, 2026.
In that post, the agency described what the new platform is for. Because the statement comes from CISA itself and is reported here secondhand, the wording matters as much as the substance.
"VINCE-NT is a modernized, CISA-managed platform for vulnerability reporting and coordination. It improves how vulnerability reporters, product suppliers and CISA case managers collaborate throughout the disclosure process," CISA said in an announcement published on social media on September 17.
— CISA, in an announcement published on social media on September 17
Beyond the platform refresh, the change shifts ownership, sponsorship and management of the system to CISA's Coordinated Vulnerability Disclosure team. CISA said the move also enables improved integration with its internal tools and processes.
What the Upgrade Adds
CISA listed a set of enhancements that come with VINCE-NT. Several are aimed at the point where a report first arrives, while others target the later stages of drafting and publishing an advisory.
- A user-friendly interface that makes submitting vulnerability reports easier, safer and reduces friction
- Enhanced triage effectiveness enabling teams to better prioritize the most critical vulnerabilities
- Simplified advisory publication workflows through automation
- Built-in tools enabling transparent collaboration among all parties while protecting sensitive data
- Enhanced reporting case metrics, giving CISA's CVD team actionable insights to improve coordination
- Stronger support for multi-party coordination and developing advisories
Taken together, the list describes a platform built to move a report from submission through triage to a published advisory with fewer manual handoffs. The submission interface and the triage changes sit at the front of that chain. The publication workflow and multi-party coordination features sit at the back, where suppliers, reporters and the agency have to agree on what gets disclosed and when.
The Vocabulary Gets Rewritten
VINCE-NT also redraws some of the terminology CISA has used until now. Three familiar labels are replaced:
- vendors/developer/maintainer becomes supplier
- product is replaced by component
- researcher/finder is now reporter
The rewording matters for anyone who files reports or reads CISA advisories, because the terms appear on forms, in case records and in published documents. A shift from "product" to "component," for instance, changes how a submission is described in the case system itself. Anyone filling in a report and looking for the old field names will need to map them to the new ones.
How Active Cases Move Over
The transition is not a clean cut for every open case. In an FAQ about the transition, CISA addressed what happens to work already underway.
Active VINCE cases will be transitioned over the coming weeks, according to the agency. For stakeholders holding an active case on the old platform, a case coordinator will reach out and convey the transition date directly. That means the timing of any individual migration is communicated one-to-one rather than through a single public cutover date.
Inactive cases will not be moved to VINCE-NT but will still be available on VINCE. So the old platform does not go dark entirely, at least for records that are no longer being actively worked.
Organizations, meanwhile, should update internal reporting procedures to reflect that vulnerability submissions to CISA should now be made through VINCE-NT, CISA said. That instruction applies to the organizations that report flaws, not just the agency's own staff.
Why the Coordination Piece Is the Hard Part
Coordinated disclosure is a multi-party exercise by definition. A reporter finds a flaw, a supplier confirms and patches it, and the agency helps synchronize what gets said publicly and when. CISA said VINCE-NT places stronger support behind multi-party coordination and the development of advisories, and it bundles in tools for collaboration that are meant to keep sensitive data protected while the parties work.
The metrics piece runs alongside that. Enhanced reporting case metrics are intended to give CISA's CVD team actionable insights to improve coordination, per the agency's list. Those are the sorts of numbers that let a coordinating body see where cases stall, though CISA has not published what the metrics cover.
What is concrete is the ownership shift. The platform is now managed by CISA's Coordinated Vulnerability Disclosure team rather than sitting with Carnegie Mellon's CERT/CC, which developed VINCE in 2020. CISA described the change as shifting ownership, sponsorship and management of the platform to that team.
Agency Control, Agency Process
The move places a system that researchers and suppliers interact with under direct agency management. CISA's own description of VINCE-NT leads with that point: it is a CISA-managed platform, and the agency frames it as an improvement to how the three main parties in a disclosure case collaborate from start to finish.
The prior arrangement dates back six years, when CERT/CC built VINCE and CISA adopted it. The new one keeps the VINCE name but changes who runs the environment and how it connects to the agency's other systems. CISA said the change enables improved integration with its internal tools and processes, which is the agency's own stated benefit of holding management directly.
For anyone who works cases with CISA, the practical surface area of the change is narrow but real: a new submission interface, new field names, and a migration that active cases will go through over the coming weeks at a date delivered by a case coordinator.
What Reporters and Suppliers Should Do
The FAQ and the announcement together point to a short list of actions for organizations that interact with CISA on vulnerabilities. Submissions to CISA should now go through VINCE-NT. Internal reporting procedures should be updated to reflect that change.
For anyone with an active case, the next step is reactive rather than self-directed: wait for the case coordinator to make contact and provide the transition date. There is no public schedule to consult, since CISA said coordinators will convey dates individually to stakeholders with active cases.
Inactive cases stay where they are, on VINCE, and remain available there. That distinction — active cases moved, inactive cases left in place — is worth noting for anyone who assumes the old platform has simply been turned off.
The terminology changes are the easiest thing to miss. A report that used to name a "vendor" or a "product" now sits in a system that calls those parties a "supplier" and a "component," and the person filing is a "reporter" rather than a "researcher" or "finder." Familiarity with the old labels will not carry over unchanged to the new submission process.
The Stakes for Everyone Downstream
Coordinated disclosure is one of the few places where a reporter, a supplier and a government agency all have to agree on a timeline before the public learns anything. CISA's platform is the machinery that holds those parties to a shared schedule. When that machinery is replaced, the immediate risk is procedural rather than dramatic: reports filed through the wrong channel, stakeholders who miss a coordinator's message, or organizations whose internal documentation still names the old platform as the place to submit.
The automation CISA describes — streamlined triage, simplified publication workflows, better case metrics — is aimed at the agency's own processing capacity, and the agency has framed it as an improvement to collaboration across the disclosure process. Whether that translates into faster or smoother handling is something only future case data will show. Neither CISA's announcement nor its FAQ offers performance figures, and none are reported here.
For the organizations that report vulnerabilities to the US government, the near-term takeaway is administrative. Confirm that the people who file reports know submissions now go through VINCE-NT. If a case is open, watch for contact from a case coordinator rather than waiting on a public date. And if a supplier, reporter or case manager throws around the word "component" where "product" used to be, that is not a new kind of object being reported — it is the same one under a new label, in a system that now answers to CISA's Coordinated Vulnerability Disclosure team.
The deeper question is what a managed, automated platform does to the tempo of disclosure over time. Better triage and built-in collaboration tools are the two ends of the same pipeline: one decides which flaws get attention first, the other governs how much the parties can safely share while a fix is still being prepared. CISA has said it wants both to work better. The evidence will be in the advisories that follow.
Sources
- Infosecurity Magazine Original source
Continue Reading
TigerByte Exits Stealth With $3M for Edge AI Defense
New Hampshire startup TigerByte Cyber emerges from stealth with $3 million in seed funding to harden legacy and edge systems for military and commercial use.
Four Kernel Flaws, Public Exploits, One Fix
A researcher published working local-root exploits for four Linux kernel bugs fixed weeks earlier, flagging a patching race for older systems.
India Tightens Grip on Caller-ID Apps
TRAI's amended rules force caller-ID apps to feed spam reports into a telecom blockchain, drawing accusations of anti-competitive data transfer from Truecaller.