New York – September 22, 2026 -- Chainguard has been authorized by the CVE Program as a CVE Numbering Authority (CNA), granting it the power to assign official vulnerability identifiers for qualifying open source flaws surfaced through its Athena coalition.
Chainguard gains authority to assign CVE identifiers for unclaimed open source flaws
The CNA scope covers cases where upstream maintainers have already fixed a flaw without issuing an identifier, where no maintainer remains to assign one, or where no more specific CNA covers the affected project. Chainguard's CVE Records will defer to maintainers and project-specific CNAs wherever they exist.
Frontier AI models are outpacing traditional vulnerability detection in open source code
Chainguard says AI systems are now surfacing latent vulnerabilities in widely used open source software that traditional security tools and years of expert review failed to catch. Quincy Castro, Chief Information Security Officer at Chainguard, said AI-driven zero-day discovery is pushing traditional vulnerability handling and disclosure processes to their breaking point.
Castro said the CNA status allows Chainguard to communicate fixes in a format already familiar to organizations and open source maintainers, speeding distribution of remediation data.
Athena coalition backs the initiative with Akamai, Cisco, JPMorganChase and other partners
The CNA designation strengthens Athena, Chainguard's industry coalition for coordinated defense of open source software, by supplying precise affected and fixed version ranges alongside technical details that help organizations assess exposure and reduce false positives. Coalition members and mitigation partners include Akamai, BNY, Cisco, Cloudflare, JPMorganChase, Kyndryl, Morgan Stanley, and Upwind. Athena validates AI-discovered vulnerabilities and develops fixes, then works with Akrites to carry them through disclosure toward upstream remediation.
Without CVE identifiers, vulnerabilities can remain invisible to the scanners, databases, and compliance systems organizations rely on to prioritize risk, according to Chainguard.