More than 500 vulnerabilities in five months is a striking pace, yet the real security story is how release cadence, browser dependencies, and AI-assisted discovery complicate the math.
ENISA’s new Root role inside the CVE Program points to a more structured European path for vulnerability assignment, but the practical impact depends on how the coordination model is used.