AGP Picks
View all

TuxCare becomes a CVE Numbering Authority

Jul. 14, 2026
By AI, Created 13:05 UTC, Jul 14, 2026, AGP -

TuxCare said July 14, 2026, that the CVE Program authorized it as a CVE Numbering Authority, giving the company the ability to assign CVE IDs and publish records for vulnerabilities in supported open-source and end-of-life software. The move is meant to speed coordinated disclosure and remediation for customers protecting critical systems.

Why it matters: - TuxCare can now act as the authoritative source for vulnerability records tied to the open-source and end-of-life software it supports. - The CNA role can shorten the path from vulnerability discovery to patch deployment for organizations relying on those technologies. - The designation addresses a common gap for end-of-life and community-driven projects where upstream maintainers may not have the resources to manage the CVE process.

What happened: - TuxCare announced July 14, 2026, that the CVE Program authorized the company as a CVE Numbering Authority. - The authorization lets TuxCare assign Common Vulnerabilities and Exposures identifiers and publish CVE Records for supported software. - TuxCare joins the global network of CVE Numbering Authorities that help maintain the CVE List.

The details: - The CVE List is a foundational resource used by organizations worldwide to identify, prioritize and address cybersecurity vulnerabilities. - For supported open-source and end-of-life technologies, TuxCare can manage vulnerabilities through a single coordinated process. - TuxCare said the process will help organizations receive timely security guidance and protection for critical systems. - Michael Canavan, TuxCare's chief revenue officer, said the designation underscores the company's ability to deliver coordinated vulnerability disclosure and remediation. - Canavan said the move also addresses a critical gap for end-of-life and community-driven projects. - The CVE Program's mission is to identify, define and catalog publicly disclosed cybersecurity vulnerabilities. - The program says standardized identification and communication of vulnerabilities helps organizations coordinate remediation and improve cybersecurity across the technology ecosystem. - More information is available through the CVE Program.

Between the lines: - The CNA status strengthens TuxCare's role in the vulnerability-management chain, not just in patch delivery. - The authorization also signals that TuxCare wants to be part of the upstream disclosure process for software it supports, especially where no active maintainer can do that work.

What's next: - TuxCare is expected to use the CNA role to assign CVEs and publish records as new issues are identified in its supported software. - The company also says it will continue offering automated rebootless vulnerability patching, end-of-life security services and enterprise support for AlmaLinux. - More information is available through TuxCare.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

The Consumer News Network

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

The Consumer News Network

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.