NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020
ID: 75891139-3a4d-5e26-9007-82a9954ae61c
STIX ID: report--75891139-3a4d-5e26-9007-82a9954ae61c
Feed Name: cybersecurityNews.com
NIST announced on April 15, 2026 that the NVD will shift from comprehensive CVE enrichment to a targeted, risk-based prioritization model: focusing immediate enrichment on CVEs in CISA’s KEV catalog, software used by federal agencies, and software designated critical under EO 14028. Lower-priority CVEs will still be published but labeled “Lowest Priority” and not immediately enriched; duplicate severity scoring will be removed when provided by the CNA, backlog items published before March 1, 2026 are marked “Not Scheduled,” and the NVD Dashboard has been updated to reflect real-time status as NIST reallocates resources and develops automation to stabilize operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
