CVE Program

RedEye Security Is Now a CVE Numbering Authority

The CVE Program has authorized RedEye Security to assign CVE IDs and publish CVE Records for vulnerabilities in its own products.

RedEye Security  |  September 7, 2026  |  4 min
Editorial hero illustration
CVE in this postCVE-2026-19490Live detections →All RedEye CVEs →
TL;DR
  • What: RedEye Security LLC has been authorized by the CVE Program as a CVE Numbering Authority (CNA), one of the organizations responsible for assigning CVE IDs to vulnerabilities and publishing the CVE Records that describe them.
  • Impact: Vulnerabilities in RedEye products now receive a CVE ID and a published CVE Record from RedEye directly, so defenders everywhere can reference, correlate, and prioritize them consistently.
  • What you can do: Report a security issue in a RedEye product to [email protected]. A valid, in-scope finding receives a CVE ID and public credit under our coordinated-disclosure policy.
  • Who it affects: Anyone running Caver, Caver Lighthouse, the RedEye ICS Exposure Scanner, or RedEye Intel Feeds, and any researcher who reports an issue in them.

RedEye Security has been authorized by the CVE Program as a CVE Numbering Authority. It is a step we take as the company that builds and operates its own security software: we hold our products to the same disclosure standard we ask of everyone else, and now we assign and publish the CVE Records for them ourselves.

CVE Program · CNA AuthorizationPublic Release
CVE Program
CVE Numbering Authority
Scope: RedEye Security products
RedEye Security LLC has been authorized by the CVE Program as a CVE Numbering Authority (CNA).
CNAs assign CVE IDs to vulnerabilities and create and publish the associated CVE Records. Each CNA has a defined scope; ours covers vulnerabilities in RedEye's own products.
Role
CNAAssigns and publishes CVE Records
Scope
Own productsCaver, Lighthouse, ICS Scanner, Feeds
Disclosure
CoordinatedCVE published in the advisory
Source · CVE Program, cve.orgAbout the CVE Program →

What a CNA Actually Is

A CVE Numbering Authority is an organization responsible for the regular assignment of CVE IDs to vulnerabilities, and for creating and publishing the CVE Record that describes each one. Every CVE Record on the CVE List is assigned by a CNA. Each CNA has a specific scope of responsibility for which vulnerabilities it identifies and publishes.

In practice, being a CNA changes how a vulnerability in one of our products travels. When an issue is found and validated, we assign it a CVE ID and publish the CVE Record ourselves, on a coordinated timeline, rather than routing it through a third party. The record carries a single, consistent description that anyone can reference, and it flows into the U.S. National Vulnerability Database and from there into the scanners and SIEMs that defenders already run.

What CVE Is, and Why It Is Worth Doing

The mission of the Common Vulnerabilities and Exposures (CVE) Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. Partners publish CVE Records to communicate consistent descriptions, so that information technology and cybersecurity professionals can be sure they are discussing the same issue, and can coordinate how they prioritize and fix it.

The value is simple and it is the reason the program exists: CVE lets two or more people or tools refer to a vulnerability and know they are talking about the same thing. That shared reference saves real time and cost, on every side of a disclosure.

Community driven

The CVE Program relies on the community to discover vulnerabilities, which are then assigned and published by partner organizations around the world. The CVE Board that sets the program's direction is drawn from industry, academia, and government internationally, and the working groups that develop program policy are open to the community. RedEye joins that community of partners as a CNA.

Our Scope

Our CNA scope is limited to vulnerabilities in RedEye Security's own products:

We assign CVE IDs only for issues in these products. A report about our websites or the content of our feeds is still accepted and fixed, but it is not CVE-eligible. For a vulnerability outside our scope, we will point you to the appropriate CNA or to the CVE Program, and we will not assign a CVE ID ourselves.

What It Means if You Run Our Products

A CVE Record is a shared reference. When we ship a fix, you can match it to a specific CVE ID, watch it flow into the National Vulnerability Database and into your own tooling, and weigh it against everything else on one scale rather than parsing a vendor's prose. That is the whole point of the program, and it is now something we do directly for our products.

We already publish our advisories openly, with no login and no registration, at redeyesecurity.com/security/advisories, and we run a coordinated-disclosure policy with a safe harbor for good-faith research. Being a CNA closes the loop: the advisory and the CVE Record are published together, and the reference you use internally is the same one the rest of the industry uses.

About the program's sponsorship

The CVE Program is sponsored by the Cybersecurity and Infrastructure Security Agency (CISA), of the U.S. Department of Homeland Security, and is operated by the MITRE Corporation in collaboration with international industry, academic, and government stakeholders. Authorization as a CNA is a role within that program; it is not an endorsement of RedEye or its products by any of those bodies.

Fix It Yourself: How to Report a Vulnerability in a RedEye Product

The announcement above is the change. This is what to do with it if you have found something. Reporting is straightforward and the audit steps below change nothing on our end.

1. Send the report

Email [email protected] with as much of the following as you have:

  • The affected product, version, or URL.
  • A clear description of the vulnerability and its impact.
  • Step-by-step reproduction, including any proof-of-concept, requests, or screenshots.
  • Your severity assessment, if you have one.
  • How you would like to be credited, or whether you prefer to stay anonymous.

2. Confirm it is in scope

CVE-eligible means a vulnerability in a RedEye product: Caver, Caver Lighthouse, the RedEye ICS Exposure Scanner, or RedEye Intel Feeds. Read the policy first; when in doubt, send it anyway.

curl -s https://www.redeyesecurity.com/.well-known/security.txt

The security.txt file is the machine-readable contact of record: reporting address, policy URL, and preferred language.

3. Check our advisories, and know which list is which

To see whether an issue in a RedEye product is already disclosed, read our published advisories at redeyesecurity.com/security/advisories. Keep two lists separate: our CVE index tracks the vulnerabilities our threat-intelligence feed and detection content cover across the industry, and it is not the list of CVE Records RedEye assigns as a CNA. That CNA list applies only to our own products and starts fresh from our authorization.

4. A prompt to triage your own finding first

Paste this into your assistant of choice to structure a report before you send it. It produces a clean write-up and, just as usefully, tells you when you do not have enough to act on yet.

I found a possible security issue in a vendor product. Help me write a coordinated-disclosure report. Ask me for: the product and exact version, the observed behavior, the security impact if abused, and the minimal steps to reproduce. Then draft a concise report with those sections, propose a CVSS 3.1 vector with a one-line justification per metric, and flag anything I have asserted that I have not actually demonstrated. Do not overstate impact beyond what the reproduction proves.

5. What to expect from us

Acknowledgement within 3 business days, an initial assessment within 10, an update at least every 14 days while the issue is open, and a fix or advisory within 90 days depending on severity. If the finding is valid and in scope, we assign a CVE ID and publish it in the advisory at disclosure, with public credit unless you ask us not to be named.

Read the disclosure policy.

Scope, safe harbor for good-faith research, coordinated-disclosure timelines, and how we assign CVE IDs for our products, all on one page.

RedEye Vulnerability Disclosure Policy