Conference Description
Key Takeaways
- VulnOptiCON 2026 is a three-day technical colloquium focused on vulnerability management, exploitation forecasting and artificial intelligence security risks
- The event takes place 23–25 September 2026 in Luxembourg, organised by the Forum of Incident Response and Security Teams (FIRST)
- Sessions address the CVE ecosystem’s future, open vulnerability tracking frameworks, threat behaviour prediction and AI-driven vulnerability discovery
- Speakers include representatives from CISA, ENISA, NCSC UK, CIRCL, academic institutions and security vendors
- The conference arrives as annual CVE disclosures have exceeded 66,000, intensifying pressure on security teams to improve risk prioritisation
Introduction
VulnOptiCON 2026 brings together vulnerability researchers, security practitioners, data scientists and academics to examine how organisations can better anticipate and manage cybersecurity risk. Organised by the Forum of Incident Response and Security Teams (FIRST), the technical colloquium takes place in Luxembourg from 23 to 25 September 2026. The event addresses a pressing challenge: with CVE disclosures now surpassing 66,000 annually, security teams require more sophisticated approaches to vulnerability prioritisation than reactive patching alone can provide.
Evolution from Vuln4Cast
VulnOptiCON represents an expansion of the Vuln4Cast conference series, broadening its scope to encompass the wider vulnerability ecosystem. The event continues the tradition of rotating through European cities each year, with Luxembourg serving as the 2026 host location. This year’s programme extends to three days, reflecting the growing complexity of vulnerability management challenges facing European and international security communities.
The Computer Incident Response Centre Luxembourg (CIRCL) serves as the local partner for the event. FIRST, the organising body, is a global membership organisation founded in 1990 that now comprises more than 868 member teams and 211 individual members across 117 countries.
Artificial Intelligence and Vulnerability Discovery
A central theme of VulnOptiCON 2026 is the impact of artificial intelligence on vulnerability discovery, exploitation and remediation. The conference theme, “The A-Eyes See All,” reflects growing concern within the security community about how AI capabilities are accelerating both the identification of vulnerabilities and the speed at which they can be weaponised.
Jaya Baloo, currently COO and CISO at AISLE and formerly CISO at Rapid7 and Avast, delivers a keynote addressing how AI is reshaping the vulnerability lifecycle. Her presentation focuses on practical defensive strategies that security teams can implement as AI-assisted exploitation becomes more prevalent. Regina Joseph, a behavioural scientist specialising in applied forecasting, presents complementary research on building forecasting units capable of predicting threat behaviour before incidents occur.
The Future of CVE and Vulnerability Tracking
Several sessions examine the structural challenges facing vulnerability identification and tracking systems. A panel titled “You, Me, and CVE: What Does the Future Hold for the CVE Program?” brings together policy leaders from CISA, ENISA and the University of Twente to discuss the programme’s evolution. The panel includes Lindsey Cerkovnik from CISA, Nuno Rodrigues Carvalho from ENISA, Jeroen van der Ham-de-Vos from the University of Twente, and Jen Ellis from NextJenSecurity.
CIRCL representatives Alexandre Dulaunoy and Cedric Bonhomme present on GCVE, an initiative aimed at creating more open and interoperable vulnerability tracking infrastructure. This session addresses how the security community might develop alternatives or supplements to existing centralised vulnerability databases.
Forecasting and Data-Driven Risk Assessment
The programme emphasises practical methodologies for moving beyond reactive vulnerability management. Ruben Bos from Volerian presents research on measuring and forecasting exploitation conditions, offering frameworks for predicting which vulnerabilities are most likely to be actively exploited. Jerry Gamblin from Empirical Security examines the data quality and governance challenges inherent in vulnerability databases, while Natalie Kilber from Haste addresses detection techniques for emerging threat categories.
These sessions reflect a broader industry shift toward probabilistic risk assessment, where security teams attempt to forecast exploitation likelihood rather than treating all vulnerabilities as equally urgent.
Audience and Participation
VulnOptiCON 2026 is designed for security practitioners working directly with vulnerability data, including incident responders, vulnerability researchers, threat intelligence analysts and data scientists. The programme also addresses the needs of policy professionals involved in vulnerability disclosure coordination and security standards development. Representatives from government cybersecurity agencies, regional CSIRTs, academic institutions and private sector security teams comprise the expected attendance.
The conference format prioritises interactive discussion over passive presentation, reflecting the organisers’ goal of enabling practitioners to compare methodologies and refine approaches collaboratively.

