TrollEye Security

Cyber News

NIST Overhauls NVD Operations, Will Stop Enriching “Lowest Priority” CVEs Amid Record Volume

Facing record CVE volume, NIST is overhauling how it runs the National Vulnerability Database, saying it will stop enriching 'lowest priority' CVEs so it can keep pace with the flood

A Risk-Based Shift Driven by a 263% Surge in CVE Submissions

The National Institute of Standards and Technology (NIST) is restructuring the way it operates the National Vulnerability Database (NVD), announcing on April 15th, 2026 that it will no longer automatically enrich every CVE it receives. Under the new risk-based model, only vulnerabilities that meet specific high-impact criteria will receive the severity scores, product lists, and additional context that security teams have long relied on. Everything else will still be published in the NVD, but flagged as “Lowest Priority – not scheduled for immediate enrichment.”

The change is due to a dramatic rise in vulnerability reporting. According to NIST, CVE submissions grew 263% between 2020 and 2025, and the first three months of 2026 were already roughly one-third higher than the same period a year earlier. NIST says it enriched nearly 42,000 CVEs in 2025, about 45% more than any prior year.

What Gets Prioritized Now

Starting April 15th, NIST will focus its enrichment resources on three categories of vulnerabilities: CVEs listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, CVEs affecting software used within the U.S. federal government, and CVEs tied to “critical software” as defined by Executive Order 14028. For KEV entries specifically, NIST says its goal is to complete enrichment within one business day of receipt.

Anything outside those categories will still be published to the NVD, but without the additional analysis many organizations depend on. Low-priority vulnerabilities will carry only the severity rating supplied by the CVE Numbering Authority (CNA) that submitted them, rather than a separate NIST score. Users can still request enrichment of specific “lowest priority” entries by emailing [email protected], and NIST says it will schedule those requests as resources allow.

Changes to Severity Scores and Modified CVEs

Beyond the prioritization overhaul, NIST is also streamlining how it handles scoring and updates. Historically, NIST assigned its own severity score to every submitted CVE, even when the submitting CNA had already provided one. Going forward, NIST will no longer routinely produce a duplicate score in those cases, though users can request one for specific entries.

The agency is also changing how it handles enriched CVEs that get modified later. Instead of re-analyzing every modification, NIST will only re-examine changes it determines materially affect the enrichment data. As part of this transition, all CVEs previously marked as “deferred” in 2025 will be moved to a new “Modified After Enrichment” status in batches over the next two weeks.

Addressing the Backlog

The NVD has been carrying a significant backlog of unenriched CVEs since early 2024, a problem that has grown increasingly visible to analysts and engineers who noticed missing or delayed analysis across thousands of entries. With the new model in place, NIST is moving all backlogged CVEs with an NVD publish date earlier than March 1 st, 2026 into a “Not Scheduled” category.

Those older vulnerabilities may still be enriched later, based on the same risk-based criteria, as resources permit. KEV-listed vulnerabilities are not part of the backlog, since NIST says it has always prioritized those entries.

What This Means for Security Teams

Teams that treat the NVD as their primary CVE feed will start seeing holes. Many new CVEs, particularly those outside KEV, federal-use software, and EO 14028 “critical software,” will ship without NIST severity scores, CPE mappings, or weakness classifications. That is a problem for any vulnerability management program that leans on NVD data to drive prioritization and SLA timelines. Workflows that used to run on autopilot will now need to plan for data that simply won’t arrive.

NIST has updated its CVE status labels and NVD Dashboard to reflect the new workflow in real time, and teams should revisit how their tooling treats CVEs in the new “Lowest Priority” and “Not Scheduled” buckets so unenriched entries do not quietly drop off dashboards and reports. Expect to lean harder on CNA-supplied CVSS scores, CISA’s KEV catalog, and vendor advisories to fill the gaps. In practice, this hands more of the analyst workload back to defenders, who now have to decide on their own which unenriched CVEs actually matter.

With NVD enrichment narrowing, moving toward continuous validation is something that is worth looking into for teams that need richer context on their vulnerabilities. An approach like Penetration Testing as a Service (PTaaS) can help fill the gaps static feeds leave behind, surfacing the context and exploitability evidence that unenriched CVEs no longer provide, so your team can understand what a vulnerability actually means in your environment rather than relying on a score that may never arrive.

Sources: NIST

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated