NIST Curbs CVE Data Amid Submission Deluge

NIST will narrow NVD CVE enrichment from Wednesday, prioritizing CISA exploited-vulnerability listings amid a sharp rise in 2026 submissions.

Jason Kwon ·

NIST Curbs CVE Data Amid Submission Deluge

The National Institute of Standards and Technology (NIST) said it is changing how it updates records in the National Vulnerability Database (NVD), citing a sharp rise in vulnerability submissions. In a statement issued on Wednesday, NIST said the volume of incoming Common Vulnerabilities and Exposures (CVE) entries has grown so quickly that its long-running practice of adding detailed metadata to each record can no longer be sustained.

NIST typically adds information such as descriptions and severity scoring to CVE records after they are published in the NVD, a step widely referred to by cybersecurity practitioners as “enrichment.” The agency said it will now reserve that work for vulnerabilities that meet a new prioritization threshold, while other CVEs will still appear in the database but without additional NIST-provided detail.

NIST said the scale of the increase has outpaced recent productivity gains. It reported that submissions during the first three months of 2026 are nearly one-third higher than the same period last year. NIST also said it enriched nearly 42,000 CVEs in 2025, which it described as 45% more than any prior year, but added that the higher output still has not matched the pace of new entries.

Under the new approach, starting on Wednesday, NIST said it will enrich CVEs that appear in a federal catalog of exploited vulnerabilities maintained by the Cybersecurity and Infrastructure Security Agency (CISA). NIST said vulnerabilities added to that catalog will be enriched within one day of notice from CISA. The agency also said it will enrich CVEs tied to products used by the federal government and software it deems “critical.”

NIST said the shift is intended to keep work focused on the most urgent vulnerabilities while it develops “the automated systems and workflow enhancements required for long-term sustainability.” A NIST spokesperson said the agency presented details on the changes the day before at the Vulncon cybersecurity conference, adding that it has received feedback and offers of support from users and that the announcement is part of an ongoing process rather than a final update.

Chris Butera, acting executive assistant director for cybersecurity at CISA, said the agency has a strong relationship with NIST and will continue collaborating to help defenders worldwide protect their networks.

Separately, experts and artificial intelligence companies have warned that wider access to AI-assisted code review tools is contributing to a growing flow of newly reported vulnerabilities, including issues described as minor, while recent AI security developments have also raised concerns about autonomous systems that can find and exploit bugs without direction.

NIST also addressed the unresolved backlog that followed staffing and funding pressures in 2024, when it said 90% of vulnerability submissions were not enriched. CISA stepped in at the time, enriching thousands of vulnerabilities on NIST’s behalf as a consortium was formed to plan ahead. A senior leader at the NVD said staffing remained unchanged at 21 people even as vulnerability counts continued to rise.

In its Wednesday statement, NIST said it has been unable to eliminate the backlog and will move all backlogged CVEs with an NVD publish date earlier than March 1, 2026, into a “Not Scheduled” category when the new criteria take effect.

NIST said it will review the backlog to identify items that meet the new threshold and prioritize those over the rest, while acknowledging that CVEs outside the criteria may still be significant and that the rules may not capture every potentially high-impact issue.

NIST said researchers can request enrichment by email. It also said it will stop issuing its own severity score for all submitted CVEs and will instead rely fully on scores provided by the submitter. NIST said the changes are meant to keep the NVD reliable, sustainable, and publicly available, while recognizing the impact on users and describing the new model as a risk-based response to the current surge.

More stories