Key Takeaways
- NIST is shifting the National Vulnerability Database (NVD) from enriching every CVE to a risk‑based prioritization model due to a 263 % rise in vulnerability submissions between 2020 and 2025.
- Immediate enrichment will focus on three categories: CVEs listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, vulnerabilities affecting U.S. federal government software, and flaws in products designated as critical under Executive Order 14028.
- All CVEs will still be published, but those outside the priority groups will carry a “Lowest Priority – not scheduled for immediate enrichment” status, potentially delaying severity scores, product mappings, and scanner updates.
- NIST will stop issuing duplicate severity scores when a CVE Numbering Authority (CNA) already provides one and will only re‑enrich previously processed CVEs when updates materially affect existing enrichment data.
- The existing backlog of pre‑March 1 2026 CVEs that remain unenriched will be moved to a “Not Scheduled” category unless they meet the new priority criteria.
- The changes aim to free analyst time for automation efforts such as AI‑assisted classification, automated CVSS scoring, and machine‑readable exploit intelligence, while urging enterprises to supplement NVD data with vendor advisories, threat feeds, EPSS scores, and internal triage.
Background: Explosive Growth in Reported Vulnerabilities
The National Institute of Standards and Technology (NIST) announced a major overhaul of the National Vulnerability Database (NVD) after observing a staggering increase in submitted Common Vulnerabilities and Exposures (CVE) entries. Between 2020 and 2025, CVE submissions rose 263 %, driven by expanding software supply chains, broader disclosure practices, growth in open‑source dependencies, and heightened security research worldwide. The first quarter of 2026 showed submissions already roughly one‑third higher than the same period in 2025, underscoring that the trend is accelerating rather than plateauing.
Current NVD Throughput and Its Limits
Despite the surge, NIST reported that it enriched nearly 42,000 CVEs in 2025 alone—a 45 % increase over any prior year—demonstrating heightened productivity. Nevertheless, officials conceded that the existing manual and semi‑manual workflows can no longer keep pace with the volume of incoming disclosures. The agency explicitly stated that “this increased productivity is not enough to keep up with growing submissions,” confirming industry suspicions that vulnerability management tools built around historical enrichment rates are being strained.
What the NVD Actually Provides
While many organizations track CVE identifiers independently, the NVD adds structured intelligence that transforms those IDs into actionable data. Historically, NIST analysts enriched each vulnerability with Common Vulnerability Scoring System (CVSS) scores, product and version mappings, weakness classifications, impact metrics, searchable metadata for automation tools, and references for remediation and exploitation context. Security teams rely on this enriched data to power vulnerability scanners, risk dashboards, compliance systems, patch‑management programs, and supply‑chain security reviews. Without enrichment, a CVE may exist publicly but offers limited practical value for defenders.
New Priority System: Which Vulnerabilities Get Enriched First
Effective immediately, NIST will prioritize enrichment for three distinct categories:
- CVEs in CISA’s KEV Catalog – vulnerabilities confirmed as actively exploited in the wild. NIST aims to enrich these within one business day of receipt.
- Software Used by the Federal Government – flaws affecting applications deployed across U.S. government environments receive accelerated handling, reflecting the push toward centralized vulnerability management and zero‑trust modernization.
- Critical Software Defined Under Executive Order 14028 – products designated as critical software following major supply‑chain incidents (e.g., SolarWinds) remain a priority class, reinforcing stricter software security standards across the federal ecosystem.
By concentrating resources on these high‑impact areas, NIST hopes to ensure that the most exploitable and nationally significant vulnerabilities receive timely, detailed analysis.
Lower‑Priority CVEs: Publication Without Immediate Enrichment
All CVE entries will continue to appear in the NVD, but many will now be labeled “Lowest Priority – not scheduled for immediate enrichment.” For vulnerabilities outside the three priority groups, this status may translate into delayed official severity scoring, missing product‑version mappings, slower integration into scanners and asset‑management tools, and a greater reliance on vendor advisories, third‑party feeds, or internal triage processes. NIST acknowledges that not every disclosed flaw poses equal risk and that focusing on the subset most likely to be exploited yields better overall security outcomes.
Ending Duplicate Severity Scoring
In a related procedural shift, NIST will cease routinely issuing its own separate CVSS score when a CVE Numbering Authority (CNA) has already provided one. Previously, NIST often recalculated scores independently, occasionally creating discrepancies between vendor and NVD assessments. By stepping back from duplicate scoring, the agency aims to conserve analyst time and reduce redundancy. Organizations that have treated NVD scores as the authoritative benchmark may need to adjust their workflows to incorporate CNA‑provided scores or to perform their own reconciliation when necessary.
Revised Handling of Modified CVEs
NIST also updated its approach to previously enriched vulnerabilities that receive later updates. Going forward, the agency will only re‑analyze a modified CVE when the change materially affects the existing enrichment data—such as newly discovered exploitation methods, expanded affected product ranges, major scoring adjustments, or corrections to attack complexity or privilege requirements. Routine metadata edits (e.g., typo fixes, minor reference updates) will no longer trigger a full re‑review, allowing analysts to focus on substantive changes.
Fate of the Existing Backlog
Perhaps the most consequential operational decision concerns the historical backlog of unenriched CVEs. NIST confirmed that any CVE published before March 1 2026 that remains pending will be moved into a “Not Scheduled” status unless it meets one of the new priority criteria. The agency acknowledged that a sizable backlog began forming in early 2024 and has not been fully cleared. This formal reset signals that NIST is abandoning the hope of processing the legacy queue under the prior enrichment model and will instead concentrate future efforts on high‑risk, current disclosures.
Why Vulnerability Counts Are Rising So Fast
Several structural forces underlie the surge in CVE submissions:
- Expanding Software Supply Chains: Modern applications incorporate thousands of open‑source components, multiplying the opportunities for flaw discovery.
- Better Security Research: Bug‑bounty programs, automated code analysis, and coordinated disclosure initiatives have grown dramatically.
- More CNA Participation: An increasing number of vendors and organizations are authorized to assign CVE IDs directly, accelerating publication rates.
- Regulatory Pressure: Governments worldwide are mandating greater transparency around vulnerability disclosure.
- Cloud and OT Growth: The proliferation of SaaS platforms, APIs, industrial control systems, and embedded devices has broadened the attack surface.
Together, these factors create a vulnerability ecosystem producing data at a pace that traditional, labor‑intensive review models cannot sustainably absorb.
Implications for Enterprises
Security leaders must adapt to a landscape where reliance on immediate NVD enrichment is no guaranteed. Organizations that have depended heavily on NVD data should consider augmenting their vulnerability‑management programs with:
- Vendor advisories and direct product security notices.
- Threat‑intelligence feeds that provide exploitability context and actor‑specific insights.
- Exploit telemetry and EPSS‑style probability models to gauge likelihood of real‑world abuse.
- Asset criticality scoring to prioritize patches based on business impact.
- Compensating‑controls analysis to mitigate risk when patches cannot be deployed immediately.
In practice, vulnerability management is shifting from a “patch everything rated high” mindset to a more nuanced, contextual risk‑management approach—mirroring NIST’s own new focus on exploitation, criticality, and national‑security relevance.
Broader Implications for National Cybersecurity
The NVD has long served as foundational infrastructure for the cybersecurity ecosystem, with countless commercial and open‑source tools ingesting its data automatically. Any alteration in coverage or timeliness therefore affects federal agencies, managed security providers, compliance teams, critical‑infrastructure operators, software vendors, and security researchers. While some experts lament the potential loss of comprehensive enrichment, many argue that prioritizing the subset of vulnerabilities actively exploited is preferable to producing low‑quality or severely delayed records for every disclosed flaw. The change aligns with a broader industry recognition that not all CVEs warrant equal defensive resources.
Automation as the Next Phase
NIST indicated that the freed analyst capacity will be redirected toward “automated systems and workflow enhancements” needed for long‑term sustainability. Likely developments include:
- AI‑assisted vulnerability classification to triage incoming CVEs rapidly.
- Automated CVSS scoring support that leverages machine learning while retaining human oversight for edge cases.
- Structured vendor data ingestion pipelines that pull CNA‑provided information directly into the NVD.
- Machine‑readable exploit intelligence feeds that enrich CVEs with real‑time exploitability signals.
- Dynamic prioritization systems that continuously reassess vulnerability scores based on evolving threat landscapes.
If successful, these upgrades could modernize how public vulnerability intelligence is maintained, ensuring the NVD remains a reliable, free resource despite ever‑growing demand.
NIST’s Core Message
Despite the operational reset, NIST stressed its continued commitment to maintaining the NVD as a free and dependable public repository. The agency framed the changes as necessary to preserve the database’s long‑term viability amid unprecedented demand. For the cybersecurity community, the takeaway is clear: the era of manually enriching every disclosed vulnerability is ending, to be replaced by a model centered on risk, exploitation, and criticality. This transition may reshape how defenders worldwide decide what to patch first, driving a shift toward more contextual, threat‑informed vulnerability management.

