Last week, the EU Agency for Cybersecurity (ENISA) released a new vulnerability database called GCVE as an alternative to the traditional CVE system.
GCVE (Global Cybersecurity Vulnerability Enumeration) is an EU-backed, decentralised vulnerability identification and tracking system designed to aggregate vulnerability data from multiple independent sources rather than relying on a single central authority.
At its core, GCVE is another public vulnerability database, but the key difference is how itβs structured. Instead of one central authority assigning vulnerability IDs, the system is decentralised. Multiple organisations can act as numbering authorities and publish vulnerability data, which is then aggregated into a single database.
The timing here is not accidental. Recent funding uncertainty around the traditional CVE programme highlighted how much the industry depends on a single system. GCVE feels like a move towards digital sovereignty and long-term resilience, particularly from a European perspective.
From what Iβve seen, this isnβt positioned as a replacement for CVE. Itβs more of a parallel system that can ingest data from many sources and expose it through open APIs. In theory, that gives researchers, vendors, and security teams more options and reduces single points of failure π
My main concern is fragmentation. More identifiers and more databases could mean extra work for tooling, automation, and vulnerability management processes. Whether GCVE simplifies things or adds another layer of complexity will depend on how well it integrates with existing workflows.
Still, itβs interesting to see change in a space that has been mostly static for years.
What do you think? π
Is GCVE a sensible backup for the vulnerability ecosystem, or does it risk creating confusion and duplication? Interested to hear other views π¬
