New CNAPulse Dashboard Tracks CNA Activity and Disclosure Trends

Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.

  • Sarah Gooding
    Sarah Gooding
3 min read
New CNAPulse Dashboard Tracks CNA Activity and Disclosure Trends

A new open-source dashboard called CNAPulse.org is tracking the publishing activity of CVE Numbering Authorities (CNAs) and flagging when disclosure rates begin to drop. The tool gives the CVE community a way to monitor who is keeping pace with vulnerability reporting and who has gone quiet.

The latest CNAPulse report, generated October 24, analyzed 509 CNAs and found 21 in Growth status, 104 Normal, 230 Declining, and 154 Inactive. The dashboard automatically refreshes every three hours and classifies each CNA based on a 30-day publishing window compared to a 12-month baseline, offering a near-real-time view of overall activity in the CVE ecosystem.

Security researcher Jerry Gamblin said he built the dashboard after noticing a slowdown from a major CNA and realizing that confirming the anomaly required manual data analysis. “The problem is that getting a quick, transparent overview of CNA activity was nearly impossible,” he wrote on LinkedIn. “When I noticed publishing lag from a major CNA, the only way to confirm the anomaly was to build a custom Jupyter notebook. That’s when I decided this shouldn’t be a one-off technical chore.”

That slowdown may have been Patchstack, the year’s most active CNA with 5,567 CVEs. Gamblin highlighted the lapse on LinkedIn last week, noting that Patchstack hadn’t published a CVE since September 26: “19 days of eerie silence, with the entire month of October spookily quiet.”

Patchstack CEO Oliver Sild later clarified in the comments that the pause was due to an internal migration. “We are in the middle of migrating over to a v2 of our internal threat intelligence and VDP platform,” he said. “It’s the biggest update we’ve ever done, so our bug bounty triage is temporarily on a slower pace. Ultimately, this will allow us to significantly expand our TI efforts and you’ll be seeing this in Q4.”

After feedback from security data researcher Jay Jacobs, Gamblin made a few refinements. The color scheme was changed to move away from a red-green palette, reducing the “good/bad” connotation and improving readability for color-blind users. CNAPulse also now includes dedicated CNA detail pages linked from the homepage that show activity trends for each organization. The Linux page demonstrates the new format.

Each CNA page shows a 12-month publishing baseline compared to recent activity. For example, the Linux CNA (kernel.org) averages 387 CVEs per 30-day period but published 572 in the latest window, a 47.8% increase. CNAPulse also tracks how long it has been since each CNA last published a CVE, with Linux showing zero days of inactivity.

Gamblin said the goal is to make CVE publication health visible at a glance. “This brings simple publishing transparency to the entire CVE ecosystem,” he said. CNAPulse follows his earlier CNA Scorecard project, which measures data completeness in CVE records. Together, the two tools offer visibility into both the volume and quality of vulnerability disclosures.

The launch comes amid renewed uncertainty around the CVE program’s future. MITRE’s 11-month funding extension is set to expire in March 2026, and multiple groups, including CISA, the CVE Foundation, and international consortia, are proposing new governance models. As CyberScoop’s Cynthia Brumfield reported this week, experts warn that any lapse or fragmentation in the CVE program could undermine the reliability of global vulnerability data. In that environment, independent projects like CNAPulse provide a measure of transparency and stability while the broader system remains in flux.

The CNAPulse source code is open on GitHub, and live dashboards update throughout the day at cnapulse.org.

Stay ahead of threats

Subscribe to our newsletter

Get notified when we publish new security blog posts!