logo

NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities

ID: a36fce09-dad0-556e-ad4b-e61952554e4c

STIX ID: report--a36fce09-dad0-556e-ad4b-e61952554e4c

Feed Name: Infosecurity Magazine (News)

Date Published: 2026-04-16

Date Updated: 2026-04-22

...
...

Executive summary: The NIST-operated NVD is overwhelmed by a surge in CVE submissions and will adopt a risk-based approach that drops routine enrichment for many pre-2026 unenriched CVEs, prioritizes vulnerabilities affecting US federal or critical software and those on CISA's KEV list, limits NVD-provided CVSS scoring when submitters already supply scores, and replaces the 'Deferred' label with 'Not scheduled'; users may request enrichment by contacting NVD.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.