logo

NIST's security flaw database still backlogged with 17K+ unprocessed bugs. Not great

ID: 41ee2d2d-3fa8-5eaf-beab-2182a2940d19

STIX ID: report--41ee2d2d-3fa8-5eaf-beab-2182a2940d19

Feed Name: The Register (Security)

Date Published: 2024-10-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

NIST’s National Vulnerability Database has missed its Sept. 30 target to return to pre-February enrichment rates, leaving roughly 17–18k CVEs unanalyzed and reducing organizations’ visibility into newly disclosed vulnerabilities. Analysis from VulnCheck and industry experts highlights ongoing operational risk, despite improvements since May and the hiring of a contractor, with CISA’s Vulnrichment project serving as a stopgap for severity scoring and related data. The backlog’s exact risk remains unclear due to limited transparency into which CVEs await processing, and stakeholders warn the slowdown is straining security processes and open-source projects that depend on NVD data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.