惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
腾讯CDC
V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
博客园 - 司徒正美
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
Vercel News
Vercel News
爱范儿
爱范儿
Last Week in AI
Last Week in AI
G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
有赞技术团队
有赞技术团队
D
DataBreaches.Net
博客园_首页
J
Java Code Geeks
云风的 BLOG
云风的 BLOG
V
V2EX
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
人人都是产品经理
人人都是产品经理

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
How NIST fumbled management of the National Vulnerability...
Zeljka Zorz · 2026-06-01 · via Help Net Security

A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD).

NIST NVD management problems

How the NVD crisis unfolded

The NVD was established in 2005 and serves as a central repository for cybersecurity vulnerability data.

When security researchers or software vendors discover a flaw in a piece of software or hardware, they submit a report through the Common Vulnerabilities and Exposures program. NIST then takes that raw submission and “enriches” it with additional analysis, including severity scores and information about which specific product versions are affected.

The enriched data is what makes the NVD useful, because cybersecurity teams rely on it to automate their defenses, prioritize which vulnerabilities to fix first, and comply with federal requirements.

The current NVD crisis traces back to February 2024, when NIST’s enrichment support contract lapsed. (The NVD analysts who perform enrichment are contractors.)

According to the findings by the US Department of Commerce Office of Inspector General (OIG), NIST had two years’ notice that it needed a new contractor but still failed to have a replacement ready in time, leaving the NVD program without adequate staffing until late November 2024.

The situation was made worse due to the Cybersecurity and Infrastructure Security Agency (CISA) not renewing financial support for the program in 2024, and the division overseeing the NVD being slow to request replacement funds from within NIST, the report says.

By the time a new contract was in place and a public commitment had been made to clear the backlog by September 2024, the number of unprocessed vulnerabilities stood at around 13,000. By the end of 2025, the backlog had grown to more than 27,000 vulnerabilities.

“We project that in 2026 the yearly total of reported vulnerabilities will surpass 60,000. This represents a nearly tenfold increase from a decade ago, further challenging NIST’s ability to resolve the backlog,” the OIG noted.

The OIG’s verdict and recommendations

The OIG identified four main problems in how NIST has handled the situation:

  • NIST did not have a strategic plan for the NVD (and has confirmed that to the investigators)
  • NIST’s enrichment process was found to be inefficient: Two tasks made up most of the enrichment workload, and one of them (calculating severity scores) was largely unnecessary, since nearly 80 percent of vulnerability submissions already included a score from the submitting party, and CISA had also been providing scores independently.
  • NIST and CISA are operating two overlapping vulnerability enrichment programs with little coordination between them. CISA launched Vulnrichment in May 2024, but both agencies used the same government contractor and, in many cases, completed the same enrichment tasks on the same vulnerabilities.
  • NIST’s communication with NVD stakeholders is poor, and its official communications are lagging.

The OIG concluded that without significant changes to how the program is run, the NVD will not be able to fulfill its mission and public trust in the database will continue to erode.

To turn the ship around, the OIG advised NIST to create a strategic plan, establish a backlog management plan with clear milestones, reduce duplicative severity scoring, coordinate with CISA to eliminate overlapping work, improve the process for external parties to contribute to the database, and develope a proper stakeholder communication strategy.

NIST now has until July 25, 2026, to submit a formal action plan and start implementing the recommendations.

A month before the report was released, NIST announced that it would institute a new approach for populating and enriching the NVD: it would continue to add CVEs into it, but prioritize “enrichment” of only the most critical CVE-numbered security vulnerabilities (i.e., those added to CISA’s Known Exploited Vulnerabilities catalog, those affecting software used within the US federal government, and those affecting critical software).

It also said it would stop routinely calculating its own severity scores and instead rely on those provided by CVE Numbering Authorities.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!