WIBU-SYSTEMS AG

09/09/2026 | Press release | Distributed by Public on 09/09/2026 00:42

Wibu-Systems Joins the CVE Program as a CVE Numbering…

2026-09-09

Wibu-Systems, a global leader in software protection, licensing, and security, has partnered with the global Common Vulnerabilities and Exposures (CVE™) Program as a CVE Numbering Authority (CNA) under the ENISA Root. Effective August 25, 2026, the company can assign CVE Identifiers (CVE IDs) and publish corresponding CVE Records for vulnerabilities affecting Wibu-Systems products.

Why CNA Status Matters for CodeMeter

The new responsibility is particularly relevant to Wibu-Systems' technological mission. Its flagship CodeMeter platform protects software and digital intellectual property against reverse engineering, piracy, unauthorized use, and tampering. It combines code encryption, integrity protection, secure key handling, access control, and license enforcement across desktop applications, cloud services, embedded devices, and industrial systems.

Because CodeMeter can become an integral part of its customers' products, operational processes, and software-based business models, the security of the technology itself demands disciplined vulnerability handling throughout its lifecycle. Clear identification, technical assessment, remediation, and coordinated disclosure are therefore essential complements to the protective mechanisms built into the technology.

"CodeMeter is designed to protect software, digital assets, and the business models built around them. This makes the security of our own technology and the way we respond when a potential vulnerability is reported an essential part of the value we provide," said Alvaro Forero, Head of Product Security Incident Response Team (PSIRT) and Security Expert at Wibu-Systems. "As a CVE Numbering Authority, we can now manage CVE assignments for our products directly within our established vulnerability handling process. This gives customers, researchers, product teams, and security professionals a precise and globally recognized reference for coordinating around the same issue."

The CVE Program provides an internationally recognized system for identifying, defining, and cataloging publicly disclosed cybersecurity vulnerabilities. A CVE ID gives each vulnerability a unique reference that can be used consistently across vendor advisories, vulnerability databases, security tools, software inventories, and customer remediation processes.

As a CNA, Wibu-Systems assumes direct responsibility for evaluating CVE eligibility within its defined scope, assigning the appropriate CVE ID, and creating and maintaining the associated CVE Record. This removes the need to request identifiers from another CNA and brings CVE assignment closer to the technical analysis conducted by the Wibu-Systems PSIRT and the responsible product teams.

From Vulnerability Report to Coordinated Disclosure

The CNA function builds on an established vulnerability management process. Wibu-Systems receives and investigates reports concerning its products, assesses their potential impact, coordinates remediation and disclosure, and publishes dedicated security advisories. Depending on the issue, these advisories can identify affected and fixed product versions, provide severity and vulnerability classifications, and describe updates, mitigations, or other recommended actions.

CVE Records and Wibu-Systems security advisories serve complementary purposes. The CVE Record provides the standardized identifier and concise vulnerability description needed by the wider cybersecurity ecosystem. The Wibu-Systems advisory supplies the product-specific technical context customers need to understand whether they are affected and what action they should take.

This combination is especially important for CodeMeter's broad deployment landscape. A vulnerability may need to be assessed differently depending on the affected component, version, license container, operating environment, attack vector, or required level of access. By connecting standardized CVE identification with detailed product advisories, Wibu-Systems can communicate these distinctions clearly without reducing a complex technical issue to an identifier or severity score alone.

Wibu-Systems operates as a CNA under the ENISA Root. The European Union Agency for Cybersecurity is the company's direct point of contact within the CVE Program and supports its alignment with the program's operational rules, processes, and defined scope.

Current Wibu-Systems security advisories and information about reporting potential vulnerabilities are available here.

CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

WIBU-SYSTEMS AG published this content on September 09, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 09, 2026 at 06:43 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]