NIST is no longer trying to fully score and contextualize most new CVEs. That breaks the old assumption that every record in the National Vulnerability Database will carry enough official detail to drive triage, so teams that wait for NVD enrichment will be left with incomplete risk data.
NIST says it will now prioritize CVEs in CISA’s known exploited vulnerabilities catalog, software used by the federal government, and critical software under Executive Order 14028. The agency says submissions rose 263% from 2020 to 2025, nearly 42,000 vulnerabilities were enriched in 2025, and first-quarter 2026 submissions are nearly one-third higher than the same period last year.
The practical shift is that unenriched CVEs will still exist, but many will arrive without the metadata practitioners have relied on for severity and context. That pushes prioritization toward CISA KEV, vendor advisories, and internal exposure data, and it makes backlog, not just exploitation, part of the risk picture.