The EU Agency for Cybersecurity (ENISA) has been stepping up its responsibilities in vulnerability handling and coordination. In recent years, the Agency has expanded its role in vulnerability management by developing a suite of services and strengthening its operational capabilities in this area.
ENISA provides services that help connect vulnerability identification, reporting, coordination, prioritisation, and mitigation into a more coherent EU vulnerability management capability.
The following vulnerability services are provided:
The European Vulnerability Database (EUVD)
The EUVD aggregates, stores, enriches, and publishes known vulnerabilities for public use. By providing this centralised source of vulnerability information, the EUVD helps users identify vulnerabilities and take appropriate mitigating measures.
The database is built with information from multiple sources, such as EU CSIRTs and ICT vendors disclosing vulnerability information via advisories, as well as relevant information from other sources, including known exploited vulnerability data maintained by ENISA together with EU CSIRTs (see EU KEV Catalogue for additional details), CISA’s Known Exploited Vulnerabilities (KEV) Catalog, and additional threat data providers.
Participation in the Common Vulnerabilities and Exposures (CVE) Program
ENISA is a partner of the CVE Program. The CVE Program’s mission is to identify, define, and catalogue publicly disclosed cybersecurity vulnerabilities. Through its participation, ENISA supports the wider objective of reinforcing, the shared global vulnerability identifier backbone on which governments, vendors, researchers, and defenders rely.
ENISA has been a CVE Numbering Authority (CNA) since January 2024. As such, the Agency can assign CVE identifiers (CVE IDs) and publish CVE Records for vulnerabilities discovered by or reported to ENISA and EU CSIRTs. By maintaining this registry service, ENISA supports EU CSIRTs in their coordination work and helps downstream users identify and take appropriate mitigating measures.
ENISA is also a CVE Root and thus a central point of contact within the CVE Program for European national authorities, EU CSIRTs Network members and cooperative partners falling under ENISA’s mandate. As a CVE Root, ENISA supports CNA candidates during the onboarding process to ensure operational readiness, clarity of scope, and alignment with the CVE Program’s requirements and rules. Through its role as a CVE Root, ENISA recruits, onboards, trains, supports, and oversees new and transferring European CNAs within its scope, handles dispute resolution where relevant, and helps ensure that CVE Program rules, guidelines, and processes are followed.
Find out more: How to become a CNA under the ENISA Root
The Single Reporting Platform (SRP) under the Cyber Resilience Act (CRA)
The CRA SRP is an online tool established by ENISA to simplify reporting obligations for manufacturers and, to the extent applicable, open-source software stewards under the Cyber Resilience Act.
The SRP allows manufacturers to electronically report actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements only once, rather than having to notify multiple national authorities. The SRP is designed to support secure, efficient reporting and coordination between manufacturers, ENISA, and the CSIRTs designated as coordinators.
The CRA reporting obligations of Article 14 for actively exploited vulnerabilities and severe incidents apply from 11 September 2026.
EU KEV Catalogue
The EU KEV Catalogue assembles a validated listing of vulnerabilities known to have been exploited during attacks targeting entities within the EU. Information about confirmed exploitation activity is provided by EU CSIRTs Network members and ENISA, and will be further enriched by reports received from manufacturers and open-source software stewards through the CRA SRP. Known exploitation information provided via the EU KEV Catalogue is synchronised with the European Vulnerability Database (EUVD).
Coordinated Vulnerability Disclosure
As the Secretariat of the EU CSIRTs Network, ENISA supports CSIRTs designated as coordinators to cooperate within the network when a reported vulnerability is assessed to have a potentially significant impact on entities in more than one EU Member State.
ENISA has published guidelines and studies to assist Member States in establishing CVD policies, as well as handbooks, good practices guides, and gap analyses.
All the above services support EU Member States, CSIRTs, manufacturers, open-source software stewards, vendors, researchers, defenders, and users. You can contact the ENISA Vuln Services team at: vuln@enisa.europa.eu
- ENISA will be at VulnOptiCON 2026 on September 23-25, 2026, in Luxembourg.The conference brings together a cross-section of global cybersecurity leadership including representatives from CSIRTs, cybersecurity agencies, such as CISA, NCSC UK, and ENISA, European CNAs, academic research institutions, security and AI startups and end-user organisations.
- VulnOptiCON 2026