Vulnerabilità · 164 giorni fa
NIST is no longer trying to fully score and contextualize most new CVEs. That breaks the old assumption that every record in the National Vulnerability Database will carry enough official detail to drive triage, so teams that wait for NVD enrichment will be left with incomplete risk data.
NIST says it will now prioritize CVEs in CISA’s known exploited vulnerabilities catalog, software used by the federal government, and critical software under Executive Order 14028. The agency says submissions rose 263% from 2020 to 2025, nearly 42,000 vulnerabilities were enriched in 2025, and first-quarter 2026 submissions are nearly one-third higher than the same period last year.
The practical shift is that unenriched CVEs will still exist, but many will arrive without the metadata practitioners have relied on for severity and context. That pushes prioritization toward CISA KEV, vendor advisories, and internal exposure data, and it makes backlog, not just exploitation, part of the risk picture.
13 fonti che coprono questa storia
NIST to stop rating non-priority flaws due to volume increase
The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes.
Risky Bulletin: NIST gives up enriching most CVEs
NIST says it won’t be enriching most CVEs, Russian hackers tried to disrupt a Swedish power plant, the EU releases its age verification ap [Read More
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
NIST limits CVE enrichment after 263% surge since 2020, prioritizing KEV and federal software, shifting thousands to “Not Scheduled.”
NIST advances CMVP modernization to close the gap between cryptographic innovation and validation capacity.
NIST Officially Stops Enriching Most CVEs as Vulnerability V...
NIST will stop enriching most CVEs under a new risk-based model, narrowing the NVD's scope as vulnerability submissions continue to surge.
NIST Revamps CVE Framework, Focus on High-Impact Vulnerabilities
NIST now focuses on high-risk vulnerabilities to improve cybersecurity and address its growing backlog of CVE submissions.
NIST cuts down CVE analysis amid vulnerability overload
The agency will only add enrichment details to CVEs in limited cases going forward, prioritizing known exploited flaws and vaguely defined ‘critical software.’
NIST is overhauling how it manages the National Vulnerability Database (NVD), switching to a risk-based model for vulnerability enrichment.
VulnCheck’s Commitment to Expanding Access to Vulnerability Enrichment | Blog | VulnCheck
In response to NIST NVD's announcement that it will significantly limit CVE enrichment starting April 15, 2026, VulnCheck reaffirms its commitment to filling the data gap through its free NVD++ community service and plans to expand coverage with CVSS scores over the next month
NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities
NIST’s National Vulnerability Database will now prioritize enriching new and exploited flaws to address the record growth of reported CVEs
NIST limits vulnerability analysis as CVE backlog swells
The agency will stop adding detailed information to vulnerabilities that don’t meet certain criteria.
NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
The National Vulnerability Database will now only analyze vulnerabilities in critical software, systems used in the federal government and those under active exploitation.
Part of the PlainSec briefing for 2026-04-17