NIST narrows CVE enrichment after 263% surge in submissions
The National Institute of Standards and Technology (NIST) has tightened how it augments entries in its National Vulnerability Database (NVD), saying it will enrich only those CVEs that meet a new set of prioritization rules. The agency said the shift is a response to a massive rise in incoming vulnerability reports.
NIST explained that CVEs failing to meet the new thresholds will still appear in the NVD but will not receive automatic enrichment. The agency attributed the policy change to a 263% jump in CVE submissions between 2020 and 2025 and warned that submissions are expected to remain high.
The new prioritization, which went into force on April 15, 2026, limits enrichment to CVEs that fall into one of three categories: items listed in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog; vulnerabilities affecting software used by the federal government; and CVEs affecting “critical software” as defined by Executive Order 14028.
Under the Executive Order 14028 definition, critical software includes products that run with elevated or managed privileges, possess privileged access to network or compute resources, control access to sensitive data or operational technology, or operate beyond normal trust boundaries while holding elevated privileges.
Any submission that does not satisfy those criteria will be labeled “Not Scheduled.” NIST says the goal is to concentrate scarce enrichment resources on vulnerabilities with the greatest potential for widespread or systemic impact, even while acknowledging some unenriched CVEs may still seriously affect individual systems.
NIST reported that submissions during the first quarter of 2026 were roughly one-third higher than in the same period last year, and the agency noted it is working at an accelerated pace to enrich reports. In 2025 NIST enriched nearly 42,000 CVEs-about 45% more than its previous annual high.
If a high-consequence CVE ends up in the “Not Scheduled” bucket, organizations can ask NIST to reconsider by emailing nvd@nist[.]gov. NIST said it will evaluate such requests and, where appropriate, schedule the CVEs for enrichment.
The agency also announced several operational adjustments to NVD processes. NIST will stop routinely assigning a separate severity score when a CVE Numbering Authority (CNA) has already provided one. Modified CVEs will only be reanalyzed if the change “materially impacts” enrichment data, although users may request reanalysis by contacting the same NVD address above.
All currently unenriched CVEs in the backlog with an NVD publish date prior to March 1, 2026 will be moved into the “Not Scheduled” status, except for CVEs that are already included in the KEV catalog. NIST has also refreshed CVE status labels and updated the NVD dashboard so status and statistics are reflected in near real time.
Industry voices reacted to the announcement. Caitlin Condon, vice president of security research at VulnCheck, told reporters that NIST’s move to a risk-based enrichment model had been signaled previously and that the public clarity around expectations is useful given the ballooning number of new vulnerabilities. She also pointed out that many vulnerabilities may now lack a clear path to enrichment for organizations that have come to rely on NIST as their primary or exclusive enrichment source.
Condon’s company’s data indicates roughly 10,000 vulnerabilities from 2025 still lack a CVSS score, and NIST is estimated to have enriched about 14,000 “CVE-2025” entries-approximately 32% of that year’s total. She argued that the volume and velocity of modern vulnerability discovery make manual enrichment impractical and that machine-speed, distributed approaches with a global risk perspective are now required.
David Lindner, chief information security officer at Contrast Security, said prioritizing only high-impact CVEs effectively ends the era when defenders could rely on a single government-managed repository for a complete risk picture. He urged organizations to shift toward proactive, threat-intelligence-driven risk management and recommended that defenders focus limited resources on the CISA KEV list and exploitability indicators. Lindner added that while this change may disrupt legacy audit workflows, it forces the industry to emphasize actual exposure over theoretical severity.