NIST Misses 2024 Deadline to Clear NVD Backlog
Blog post from Socket
NIST has missed its deadline to clear the National Vulnerability Database (NVD) backlog, with the number of Common Vulnerabilities and Exposures (CVEs) awaiting analysis increasing by 33% since June 2024. Despite contracting cybersecurity firm Analygence for $865,657 to aid in processing these vulnerabilities, the backlog has grown to nearly 18,000 CVEs, as the influx of new vulnerabilities outpaces analysis efforts. The lack of updates from NIST, coupled with the backlog's impact on timely vulnerability information dissemination, raises concerns about exposed systems. While some progress has been made, such as the adoption of CISA's Vulnrichment for CVSS enrichment, the overall challenge remains formidable, exacerbated by a 33.8% year-over-year increase in CVEs. Legislative proposals to include AI system vulnerabilities in the NVD could further strain resources, necessitating a transparent strategy to enhance the CVE processing system and improve national cybersecurity.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.