Connect with us

Hi, what are you looking for?


Sophos named Common Vulnerability and Exposure Numbering Authority

With this status, Sophos is authorized to assign CVE identification to unique vulnerabilities within the scope of its products. Security researchers can now work directly with Sophos to open CVEs for the company’s products, making the process of reporting issues and assigning CVEs more straightforward.

Sophos, a global player in next-generation cybersecurity, announced that it has been named a Common Vulnerabilities and Exposures (CVE) Numbering Authority (CNA) in the CVE program, a recognized international standard for identifying and naming cybersecurity vulnerabilities.

With this status, Sophos is authorized to assign CVE identification to unique vulnerabilities within the scope of its products. Security researchers can now work directly with Sophos to open CVEs for the company’s products, making the process of reporting issues and assigning CVEs more straightforward.

The CVE program is an international, community-based effort that maintains a community-driven, open data registry of vulnerabilities. The program catalogs CVEs in a publicly available registry that is available to security researchers, vulnerability disclosure and information technology vendors. Using a common identifier makes it easier to share and cross-check data across the industry’s several and separate security databases and tools that track vulnerabilities. 

“Sophos’ new status as a CNA is another example of our commitment to be transparent, and by having the ability to assign CVEs, we can provide the industry with pertinent information about our products faster. This allows organizations to more quickly assess security issues, determine the scale of urgency and prioritize updates,” said Ross McKerchar, vice president and chief information security officer at Sophos. “Sophos’ CVEs will also get entered into the multiple CVE-compatible databases within the industry. By working collectively on these databases with other vendors and industry standards watchguards, we can together improve defenses against persistent attackers.”

Advertisement. Scroll to continue reading.

“The Common Vulnerabilities and Exposures Team welcomes Sophos as our newest CVE Numbering Authority. Sophos has a strong reputation of contributing to the global digital security community, producing antivirus, encryption and cybersecurity capabilities for over 30 years. Their experience brings real value to the CVE Program. We are very pleased to have Sophos as a contributing member of the CVE Team,” said Kent Landfield, CVE board member.


Like Us On Facebook

You May Also Like


Using SubWave sonar technology, divers can use Descent X50i to communicate with one another underwater and monitor each other’s tank pressure, depth, and distance...


Huawei earns the title of industry overall leader with a high score of 86.4, topping the world in market share, innovation, and application capabilities.


“We are honored he (Dennis Uy) accepted our invitation to lead the conference this year. He will be ably guided and supported by the...

Biz Solutions

Designed to meet the evolving demands of B2B clients, the platform now offers the LG DOOH Ads advertising solution for digital signage products, as...


Ascendion aims to create at least 6,000 new jobs in the Philippines, leading to an estimated economic impact of at least $500 million over...


With the theme "From Milestones to Horizons: Strengthening the Future of the Legal Profession", the biennial event drew an audience of around 4,000 lawyers...


The certification validates that the said infrastructure was able to meet stringent design standards for redundancy, maintainability, and uptime reliability.


The representatives discussed enhancing financial access for all Filipinos through the promotion of financial inclusion and education. Additionally, they explored strategies to enhance consumer protection by...
