logo

Federal audit reveals NIST’s NVD is plagued by poor planning and duplication

ID: 0fb8f899-afcb-558f-8c26-a75cf3439f6f

STIX ID: report--0fb8f899-afcb-558f-8c26-a75cf3439f6f

Feed Name: CyberScoop

Date Published: 2026-05-29

Date Updated: 2026-05-30

Author: Greg Otto

...
...

The Department of Commerce inspector general found that NIST mismanaged the National Vulnerability Database: an enrichment contract lapse and poor planning caused a backlog to grow from ~13,000 to over 27,000 unprocessed vulnerabilities, analysts spent most time on redundant severity scoring and manual product identification, and uncoordinated work with CISA produced at least 21,000 duplicated cases. The report recommends a long-term plan, a clear backlog-clearing schedule, reduced unnecessary severity scoring, improved tooling and third-party contribution paths, coordination with CISA, and better user communication; NIST agreed and must submit a remedial plan by late July.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.