惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
腾讯CDC
D
Docker
The Cloudflare Blog
量子位
爱范儿
爱范儿
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Vercel News
Vercel News
MyScale Blog
MyScale Blog

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities
Kevin Poireault · 2026-04-16 · via www.infosecurity-magazine.com

The team behind the US National Vulnerability Database (NVD) can’t keep up with the explosion of new reported vulnerabilities, said a top official of the US National Institute of Standards and Technology (NIST), which hosts the database.

Speaking at VulnCon26's in Scottsdale, Arizona, on April 15, Harold Booth, a NIST computer scientist, said the NVD had to make operational adjustments in how its data analyst enrich vulnerabilities to address the “record growth” of reported common vulnerabilities and exposures (CVEs).

“CVE reporting keeps increasing – and trust me, at the NVD, we see them all – and our ability to keep up is just not there, so our backlog keeps increasing too,” Booth said.

The data analyst will thus shift to a risk-based approach that will guide how they prioritize which CVE to process and enrich first.

This new approach implies bold moves, including the NVD dropping routine enrichment for all currently unenriched vulnerabilities reported before March 1, 2026.

Additionally, the NVD will prioritize enriching vulnerabilities found in software used by the US federal government or in critical software as defined by the Executive Order 14028, published in 2021.

The NVD will also give precedence to vulnerabilities included in the US Cybersecurity and Infrastructure Agency’s (CISA) Known Exploited Vulnerabilities (KEV) list.

“All submitted CVEs will still be added to the NVD. However, those that do not meet the criteria above will be categorized as ‘Not Scheduled,’” said Booth.

“Vulnerabilities are a way for an attacker to gain access to a system that they should not and we want to close those holes as quickly, efficiently and effectively as possible. We want to focus on the ones that are important, not the ones that are unimportant,” he added.

Users can request enrichment of any unscheduled CVEs by emailing the NVD at nvd@nist.gov.

The CVE Surge Threatens NVD Capacity

This change is driven by a surge in CVE submissions, which has increased by 263% between 2020 and 2025, according to a NIST statement published on April 15.

Booth said the NVD is “working faster than ever” and enriched nearly 42,000 CVEs in 2025, 45% more than any prior year. However, they cannot catch up with the speed at which CVE’s get reported.

“Submissions during the first three months of 2026 are nearly one-third higher than the same period last year. We’ve been trying to develop new tools to help with this, but with our current methods, I will admit this is just something we can’t keep up with,” Booth said during VulnCon.

CVE production trends. Source: US National Institute of Standards and Technology
CVE production trends. Source: US National Institute of Standards and Technology

This is trend is likely to accelerate. In February 2026, the Forum of Incident Response and Security Teams (FIRST) forecast a record-breaking 50,000 additional CVEs to be reported in 2026.

Jerry Gamblin, principal engineer at Cisco Threat Detection & Response, expects an even bigger growth, with a forecast of 70,135 CVEs by the end of this year. This would reflect a 45.6% growth rate compared to 48,171 in 2025.

These forecasts do not consider recent announcements by Anthropic and OpenAI of new generative AI models – namely Claude Mythos and GPT-5.4-Cyber – that promise to autonomously find and fix cybersecurity vulnerabilities at scale.

Booth acknowledged that his team also faced a growth in the number of Common Platform Enumeration (CPE) identifiers largely due to new vulnerability discovery tools based on large language models (LLMs).

CPE is a standardized naming scheme used to uniquely identify hardware, operating systems and software applications.

New Rules for CVE Scoring and Analysis

Booth also revealed other changes in how the NVD will now enrich CVEs, following the same risk-based approach.

The NVD will no longer provide its own severity scores (CVSS) for CVEs already scored by the submitting authority, unless they deem the score doesn’t align with the vulnerability.

Additionally, the NVD will only reanalyze modified CVEs if changes materially impact enrichment data.

Users can request a score change or a new CVE analysis by contacting the NVD, which will review the submission and decide how to process on a case-by-case basis.

Finally, Booth also announced updated status labels for CVEs to “make them clearer.” For instance, the NVD will drop the previous ‘Deferred’ status and replace it with ‘Not scheduled’ to indicate the NVD will not enrich the corresponding CVE.

The NVD has published a document explaining CVE and NVD status labels, what they mean and how they compare.

NVD status workflow diagram. Source: US National Institute of Standards and Technology
NVD status workflow diagram. Source: US National Institute of Standards and Technology