AI Briefing
KO

NIST Gives Up on Enriching Most CVEs

·2026.04.18 00:09

Key point

NIST is scaling back NVD enrichment to focus on critical vulnerabilities.

Details

NIST has announced a change to its NVD (National Vulnerability Database) enrichment policy: going forward, it will no longer enrich every CVE, and will instead prioritize enriching only critical vulnerabilities.

Enrichment will be narrowed to three categories:

  • Vulnerabilities listed in CISA KEV that are being actively exploited
  • CVEs for software used by U.S. federal agencies
  • CVEs for software NIST classifies as critical software

While "critical software" sounds narrow by name, it actually covers a broad range of core infrastructure software, including operating systems, web browsers, security software, firewalls, backup software, and VPNs.

The backdrop is the NVD backlog that has persisted for over two years. In early 2024, the number of un-enriched CVEs stood at around 2,100, but by the end of the year it had swelled to nearly 30,000. Even now, NIST remains tens of thousands of vulnerabilities behind.

With this move, NIST is effectively giving up on catching up with all CVEs, and is shifting to operating with a focus on critical vulnerabilities within the limits of its resources and budget. At the same time, NIST is discontinuing the independent CVSS scores that NVD used to provide, and will instead simply display the score originally assigned by the CVE-issuing organization.

This change has a major impact on the vulnerability management industry. In particular, vendors who have built scanners, dashboards, and reporting on top of NVD output can no longer rely on a single source, and will need to find other data sources or build their own enrichment logic. The article notes that as AI-driven vulnerability discovery increases, the number of CVEs is expected to surge even further, making this shift in direction a realistic one.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.