logo

NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

ID: fb3796cc-beb3-530d-af1b-6224b719e181

STIX ID: report--fb3796cc-beb3-530d-af1b-6224b719e181

Feed Name: The Hacker News

Threat Score
0/100

Date Published: 2026-04-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

NIST announced a shift to risk-based prioritization for CVE enrichment effective April 15, 2026: only CVEs in CISA's KEV, those for federal-use software, or for 'critical software' as defined by EO 14028 will be routinely enriched; other CVEs will be marked 'Not Scheduled' though enrichment can be requested. The change includes stopping routine separate severity scores when CNAs provide them, reanalysis only for material changes, and moving older unenriched CVEs (pre–March 1, 2026) into the Not Scheduled category, prompting industry commentary about the need for more distributed, threat-driven vulnerability management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.