AppCheck Statement on CVE Funding Cuts: Continued Vulnerability Intelligence Assurance for Our Clients

The recent news regarding funding cuts to the Common Vulnerabilities and Exposures (CVE) service, run by the MITRE Corporation and backed by the US government, has understandably raised concern across the information security community. CVE has long served as a cornerstone of the cyber security ecosystem, providing unique identifiers for publicly disclosed vulnerabilities and helping standardise communication across vendors and organisations.

At AppCheck, we want to reassure our clients that our vulnerability scanning and intelligence services remain robust, resilient, and unaffected by this development.

 

AppCheck Is Not Reliant on the CVE Service

While we fully recognise the important role CVE has played in the industry, AppCheck has never relied solely on the CVE programme for vulnerability intelligence. Instead, we have built a comprehensive and independently curated vulnerability database, informed by a wide range of reliable and diverse sources:

  • Direct relationships with CVE Numbering Authorities (CNAs), many of whom continue to publish disclosures irrespective of CVE centralisation
  • Data feeds from software vendors, source code repositories, and public vulnerability databases
  • Ongoing monitoring of security advisories, research blogs, and independent disclosure platforms
  • Proprietary AppCheck research and analysis, enabling us to identify and enrich vulnerabilities beyond what is publicly documented

 

This multi-source approach allows us to detect and prioritise vulnerabilities even if CVE coordination is disrupted or delayed.

 

Our Commitment to Accurate, Up-to-Date Vulnerability Detection

Our scanning engine processes data from over 20 independent feeds, consolidating and enriching it into actionable intelligence within our own dedicated vulnerability knowledge base.

By investing in our own research infrastructure and maintaining independence from any single source, AppCheck ensures that our customers continue to receive the highest level of vulnerability coverage — including emerging threats, zero-day vulnerabilities, and misconfigurations.

 

What This Means for You

While the potential disruption to the CVE system is significant for the wider industry, AppCheck clients can remain confident that:

  • Vulnerability detection will continue seamlessly
  • Our coverage will remain broad, current, and enriched with contextual data
  • Our internal systems are designed to adapt to changes in the threat intelligence landscape

 

We are closely monitoring the CVE situation and will continue to refine and reinforce our processes as needed. Our priority remains clear: to deliver industry-leading security scanning and vulnerability management to our customers — regardless of shifts in external data sources.

If you have any further questions or would like to learn more about our threat intelligence infrastructure, please don’t hesitate to get in touch with our team.

The AppCheck Team

 

Get started with Appcheck

No software to download or install.

Contact us or call us 0113 887 8380

About AppCheck

AppCheck is a software security vendor based in the UK, offering a leading security scanning platform that automates the discovery of security flaws within organisations websites, applications, network and cloud infrastructure. AppCheck are authorised by the Common Vulnerabilities and Exposures (CVE) Program as a CVE Numbering Authority (CNA)

No software to download or install.
Contact us or call us 0113 887 8380

Start your free trial

Your details
IP Addresses
URLs

Get in touch