we_are_coded.by CODE · The world, decoded
БГ
Concept

CVE

The BasicsUpdated on 16 August 2026we are coded

The number every discovered hole in software gets, so the whole world can talk about the same thing - from the researcher who finds it to you, installing the patch.

Checked on16 August 2026
In short: CVE (Common Vulnerabilities and Exposures) is the numbering system for software holes, run by the US organisation MITRE since 1999. A CVE is the number given to every officially confirmed hole in software, so everyone - the company writing the patch, the researcher who found it, and you, installing the update - can talk about the same thing. It looks like this: CVE-2026-1234. Without it, everyone calls the problem something different, and total chaos breaks out over who's fixing what.

CVE (Common Vulnerabilities and Exposures) is a registration number for security holes. It's issued by MITRE - a private US research company, paid by CISA, the US cybersecurity agency, to maintain this list as a public service. Someone finds a vulnerability - say, in a popular WordPress plugin - reports it, MITRE reviews it and slaps a number on it. From that moment on, the whole world uses exactly that number when talking about the problem.

In practice it works like this: news breaks that a program has a serious hole. It says CVE-2026-xxxx in it. You open your antivirus program or your phone's update and see the same number in the fix notes. Do they match - then the patch addresses exactly that threat. Don't they match - then you're still exposed to it, no matter what else you've installed.

The system has existed since 1999, because before it every company named vulnerabilities however it saw fit - some numbered them, others slapped names on them, others didn't acknowledge them publicly at all. The result was that scanning tools couldn't be sure whether two reports about the same hole were actually the same thing. CVE brought order: one number, one hole, no synonyms.

It's used, quite literally, by everyone who works in security professionally - antivirus companies, IT departments patching servers, insurers, even government agencies, before they allow a piece of software to be used. The entire market of vulnerability scanning tools is built on the assumption that the CVE number is a stable, shared point of reference.

In 2026 the system shook badly - MITRE's funding from the US government hung by a thread until it was confirmed at the last moment. At the same time the EU and another international coalition launched their own numbering systems, as insurance in case the American one collapses. A symptom of something deeper: the whole internet relies on one number, issued by one organization, paid for by one government.

The CVE number isn't bureaucracy - it's the reason the world can even talk about the same hole before some bad actor has used it.

Here's the number

I like systems that solve a boring but fundamental problem - how to name something so everyone understands what's being talked about. CVE does exactly that for the most dangerous kind of information: exactly where the hole in the wall is, before the hole gets used.

What worries me is the fragility - a whole global industry depends on one organization's funding. This spring we saw what happens when the money runs out - and why the EU rushed to build a backup.

The visual is generated code art. No third-party images.
Official primary sources
→CVE Program: about the program (MITRE, since 1999)