Quick Facts

  • NIST abandons full analysis of all CVEs in favor of risk-based triage as submissions jumped 263% between 2020 and 2025
  • The agency will prioritize CVEs in CISA’s Known Exploited Vulnerabilities catalog, federal government software, and critical infrastructure
  • All unenriched CVEs before March 1, 2026 will be moved to ‘Not Scheduled’ category as NIST struggles with 21-person team

The National Institute of Standards and Technology abandoned its goal of fully analyzing every vulnerability submission to the National Vulnerability Database. The agency shifted to a risk-based triage model effective April 15, 2026, as CVE submissions hit record levels.

CVE submissions surged 263% between 2020 and 2025. Submissions during the first three months of 2026 are nearly one-third higher than the same period last year. NIST enriched nearly 42,000 CVEs in 2025, up 45% year-over-year.

The agency will prioritize three categories of vulnerabilities: CVEs in CISA’s Known Exploited Vulnerabilities catalog, CVEs for federal government software, and CVEs for critical software defined by Executive Order 14028. NIST aims to enrich KEV catalog entries within one business day of receipt.

Resource Crisis Forces Change

NIST’s staff remained at 21 people while vulnerability submissions continued growing each year. The agency developed a significant backlog starting in early 2024. All CVEs with an NVD publish date before March 1, 2026, that remain unenriched will be moved to the ‘Not Scheduled’ category.

‘We’ve been kind of caught on our heels for the last year and a half,’ Jon Boyens, whose division manages the NVD, told board members. The enrichment work is ‘very labor-intensive’ and ‘not scalable to the amount of CVEs that we’re getting in there.’

Industry Adapts to New Reality

Security experts say the change reflects longstanding industry challenges. Shane Fry, chief technology officer at RunSafe Security, called the announcement ‘a signal to the industry that the era of waiting for a CVE score before acting has come to an end.’

Bugcrowd’s Trey Ford said NIST is ‘acknowledging something the research community has understood for years: you cannot centralize vulnerability triage at this volume and expect it to hold.’

To address the gap, CISA’s Vulnrichment program now embeds metadata directly in CVE JSON feeds as of January 2025. Many organizations are turning to commercial vulnerability management platforms, though these tools are often expensive for smaller institutions.

Long-Term Strategic Shift

NIST plans to transfer vulnerability-enrichment work to CVE Numbering Authorities, representing ‘a large reset’ for the agency that has analyzed vulnerability data for more than 20 years. Budget cuts and funding challenges contributed to the crisis, with NIST experiencing a 12% budget cut and CISA pausing its $3.7 million annual NVD funding in late 2023.

‘Our foundation is research, development, and moving application of technology out to the broader marketplace,’ Boyens said. ‘The operational side, we’ve found very costly and outside of our bailiwick.’

Read more: NIST shifts National Vulnerability Database to risk-based triage as CVE submissions hit record levels

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.