Coordinated Vulnerability Disclosure (CVD) is an ongoing challenge. We are discussing CVD in vendor forums and in-house to identify the problems and sensitivities associated with changes to the process. Our experience indicates that once more than 5 vendors are involved, our current CVD process struggles with tracking the data and communications associated with these reports. We see these types of reports about 4 times a year and expect it to increase. There are no COTS solutions that can manage the multi-vendor problem.Specific questions include: Can vendors work in a collaborative environment (like GitHub)? Is encryption helping or hindering discussions? How can we continue to encourage coordinated disclosure by reporters?We expect other CERTs already have, or soon will have to solve this problem. We hope to encourage a “coordinating” solution!