NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets
Blog post from Socket
NIST has announced a shift to a risk-based enrichment model for the National Vulnerability Database (NVD), prioritizing vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog, those used by the federal government, or critical software under Executive Order 14028, while labeling others as "Not Scheduled." This change, revealed at VulnCon, comes in response to a significant increase in CVE submissions, which have surged 263% from 2020 to 2025, outpacing NIST's capacity despite a heightened output. Security experts have raised concerns about the implications of this policy, noting that it may leave many exploited vulnerabilities unenriched and highlighting disagreements between NVD and other platforms like GitHub on CVSS scores. The shift to CNA-provided scores and the potential impact of AI-driven vulnerability discovery, such as the Anthropic Glasswing/Mythos initiative, further complicates the vulnerability disclosure pipeline, leading to skepticism about NIST's ability to manage future demands without significant automation and workflow improvements.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.