惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
H
Help Net Security
N
Netflix TechBlog - Medium
Apple Machine Learning Research
Apple Machine Learning Research
P
Proofpoint News Feed
A
About on SuperTechFans
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
宝玉的分享
宝玉的分享
aimingoo的专栏
aimingoo的专栏
F
Fortinet All Blogs
博客园 - 【当耐特】
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
I
InfoQ
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog RSS Feed
U
Unit 42
The Cloudflare Blog
Y
Y Combinator Blog

Threat Intelligence Blog | Flashpoint

How Natural Language Search Powers Rapid Physical Security Intelligence The Flashpoint Threat Intelligence Brief: Middle East Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact Insider Threat Report: Dark Web Recruitment & Access Trends Navigating AI-Driven Cyber Threats: Insights from Flashpoint’s 2026 GTIR Midyear Edition Data Center Physical Security: Mitigating FPV Drone Threats Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases Flashpoint EASM: Industry-Leading Vulnerability Intelligence, Mapped to Your Internet-Facing Assets Demystifying The Com and Nihilistic Violent Extremism: What You Need To Know The Flashpoint Method: Prioritizing Vulnerabilities in an Era of AI-Accelerated Discovery Understanding Illicit Ecosystems: Inside Rehub’s Rise as a Primary Ransomware Marketplace Inside Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer Understanding Illicit Ecosystems: How Dark Web Forums Structure Cybercrime AI, Trust, and the Future of Threat Intelligence Remus Stealer: A New, Not-So-New Infostealer America250 Fourth of July Threat Assessment Unmasking the Digital Trail: Essential Techniques for Vetting AI-Generated Content The Shift to Threat-Informed Prioritization: Operationalizing CISA BOD 26-04 Identity Is the New Attack Surface: How Infostealers Are Reshaping Enterprise Risk Understanding Illicit Ecosystems: Weaponizing Mainstream Apps and Social Infrastructure Connecting Vulnerability Intelligence to Real-World Exposure With Flashpoint EASM Understanding Illicit Ecosystems: XSS and the Current State of the Russian-Speaking Underground How to Align and Measure Threat Intelligence Operations: Flashpoint Priority Intelligence Requirements The Mini Shai-Hulud Worm and the New Era of CI/CD Exploitation Understanding Illicit Ecosystems: The Hybrid Threat of “The Com” AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communities How Mergers and Acquisitions Expand Your Attack Surface Overnight The Evolution of the Geotag: How AI is Bridging the Gap in Location-Based OSINT Navigating the Threat Landscape of the 2026 FIFA World Cup
What the NVD ‘Slowdown’ Means For You: How to Stay Ahead ...
Flashpoint · 2026-04-02 · via Threat Intelligence Blog | Flashpoint

Updated April 2026.

National Vulnerability Database (NVD): Overview

The total number of reported vulnerabilities has increased by 318% since the inception of the National Vulnerability Database (NVD) in 2005, with last year reporting an all-time high of 33,137 disclosures. However, the complexity and exploitability of vulnerabilities has also risen, in addition to increasing totals and rates of disclosures. This has made it harder for organizations to manage risk effectively. 

Security teams need a comprehensive and timely vulnerability intelligence solution to perform the entire gamut of vulnerability management (VM). Without it, VM professionals are hard-pressed to stave off threat actors, since without context, it is nearly impossible to properly research and prioritize issues as vulnerability totals reach new heights every year.

What is the NVD?

You may be afraid to ask, but what is the NVD? The National Vulnerability Database (NVD) is the U.S. government repository of standards-based vulnerability management data, synchronized with the CVE (Common Vulnerabilities and Exposures) list.

NVD Shortcomings

For many organizations, relying solely on the NVD creates dangerous security gaps:

  • Significant Delays: It can take the NVD days or even months to publish analysis on a new vulnerability. For example, Flashpoint reported on a Fortinet vulnerability (CVE-2025-24472) 35 days before the NVD.
  • Incomplete Coverage: The NVD only tracks vulnerabilities that have been assigned a CVE ID. Flashpoint’s research indicates that the NVD misses over 100,000 vulnerabilities found in other software and third-party libraries.
  • Lack of Context: NVD data is often static. It provides a severity score (CVSS) but lacks real-world context, such as whether a vulnerability is currently being exploited by ransomware groups or discussed in illicit communities.

In fact, as of April 2026, under a new model announced by the National Institute of Standards and Technology, NVD will no longer enrich every CVE. Instead, enrichment efforts will focus on a defined subset, including vulnerabilities in the CISA KEV catalog, software used by the federal government, and software designated as critical. This will widen the gap between what frameworks require and what NVD can deliver.

Flashpoint’s vulnerability intelligence solution (known as VulnDB) is designed to augment NVD intel and provide intelligence built on over 415,000 vulnerabilities and rapid time from disclosure to publication (on average 2 weeks faster than NVD).

What is the NVD Slowdown?

In this blog, we delve into the NVD’s recent slowdown, its impact on vulnerability management practices, and how Flashpoint’s comprehensive vulnerability intelligence offers a timely, effective alternative for navigating these challenges.

On February 15, the maintainers of NVD, the National Institute of Standards and Technology (NIST), posted a cautionary notice on their website stating:

NIST is currently working to establish a consortium to address challenges in the NVD program and develop improved tools and methods. You will temporarily see delays in analysis efforts during this transition. We apologize for the inconvenience and ask for your patience as we work to improve the NVD program.

While this message went unnoticed initially, for the past month several vulnerability researchers and intelligence providers have noticed a severe drop in NVD-enriched vulnerabilities, as well as increases in issues awaiting analysis.

Across the board, the industry is observing severe drops in the quality or inclusion of the following metadata, including, but no limited to, CVSSv3 scoring, exploit details, remediation details, and CPEs.

Does the NVD slowdown affect Flashpoint?

Flashpoint is not affected by NVD’s slowdown, as our offerings and services have never relied on NVD for their processes for analysis. NVD’s past and current challenges have no effect on Flashpoint’s vulnerability aggregation, coverage, and publication.

NVD (and by extension, CVE) provides an essential service and has been instrumental in categorizing and standardizing the naming of vulnerabilities. Both have vital roles in the cybersecurity industry, with nearly every vulnerability management framework relying on them to some capacity—whether it be consuming CVE/NVD data directly, or unknowingly contracting an intelligence provider who repurposes their data behind the scenes.

However, CVE and NVD are not without their flaws. Even before the start of the NVD slowdown, NVD has been significantly behind in analysis of the growing number of disclosures for years, often ranging from two to six weeks to analyze a given vulnerability. Over time, this gap in coverage has culminated to over 100,000 vulnerabilities missed by CVE and NVD.

Flashpoint’s vulnerability intelligence is two weeks faster than NVD, on average, in both scoring and analysis of vulnerabilities. Our premier vulnerability database, VulnDB is independently researched and provides our customers with the latest and most detailed information, including an extended classification system, CVSS scoring, CPE strings and proprietary metrics such as Vulnerability Timeline and Exposure Metrics (VTEM), social risk, and ransomware likelihood.

What Does the NVD Slowdown Mean for You?

Organizations heavily relying on NVD need to seek an alternative source for vulnerability intelligence. While it is unknown for exactly how long this slowdown will last, it is highly likely that it will continue through the year.

Although NVD has stated that analysis will continue for the most significant vulnerabilities, we must remember that the entire commercial market does not rely on the same systems. Historically, there have been many underserved markets in terms of vulnerability coverage, and NVD’s latest statement likely means that these niche industries will see a noticeable decline in analysis.

Ultimately, in order to make risk-based decisions, you need context. Therefore, security teams will need a comprehensive, timely, and actionable source of vulnerability intelligence. How can you make that differentiation?

Your vulnerability intelligence provider should be able to give your teams unique insights—whether it be in the form of technical notes or vulnerability metadata that cannot be easily found. Here are just a few services and differentiators that can improve the effectiveness of your vulnerability management program:

  1. Technical analysis
  2. Corrected CVSS scores
  3. Breakdown of affected products and versions
  4. Inclusion of third-party vulnerabilities
  5. Open and proprietary data models that add context
  6. Threat actor chatter

Manage Vulnerability Risk Effectively with Flashpoint

NVD’s recent slowdown has highlighted the critical importance of comprehensive, timely, and actionable vulnerability intelligence. While NVD’s challenges will likely persist for an uncertain duration, it is imperative that organizations take the initiative to seek a proper source of data. For over a decade, Flashpoint has remained committed to providing comprehensive, evidence-based vulnerability intelligence to help our customers confidently assess, prioritize, and reduce risk. Sign up for a demo today.

Frequently Asked Questions (FAQs)

What is the NVD slowdown and how does it impact security teams?

The NVD slowdown refers to the significant delays in vulnerability analysis currently experienced by the National Institute of Standards and Technology (NIST). This impacts security teams by creating a lack of critical metadata—such as CVSS scores and CPE strings—needed for prioritization. Without this information, teams relying on public data are unable to accurately assess which new software flaws pose the greatest risk to their environment.

Intelligence LayerImpact of NVD Slowdown
CVSS ScoringSevere drops in the availability of severity ratings for new CVEs.
MetadataDelays in identifying affected products (CPEs) and remediation steps.
Risk VisibilityIncreased number of vulnerabilities sitting in an “Awaiting Analysis” state.

Does Flashpoint rely on NVD or CVE for its vulnerability data?

Flashpoint does not rely on NVD or CVE for its vulnerability aggregation or analysis. Flashpoint’s VulnDB is powered by an independent research team that hunts for and catalogs vulnerabilities across thousands of sources. This ensures that Flashpoint’s coverage, enrichment, and publication remain unaffected by any disruptions or funding challenges facing public programs.

  • Independent Research: Flashpoint uses its own team to verify and score every entry.
  • Superior Speed: Flashpoint provides analysis an average of two weeks faster than the NVD.
  • Broad Coverage: VulnDB includes over 100,000 vulnerabilities that are entirely missing from public lists.

Why is Flashpoint VulnDB a better alternative during public database disruptions?

Flashpoint VulnDB is a better alternative because it provides uninterrupted access to high-fidelity vulnerability intelligence regardless of NIST’s status. Beyond standard CVE data, Flashpoint offers proprietary metrics—such as Vulnerability Timeline and Exposure Metrics (VTEM) and Social Risk scores—that give security professionals the context needed to make better prioritization decisions while public systems are stalled.

Flashpoint DifferentiatorSecurity Benefit
VTEM MetricsTracks the time from disclosure to exploit availability for better planning.
Social Risk ScoreMonitors threat actor chatter on illicit forums to identify trending exploits.
Ransomware LikelihoodFlags vulnerabilities that are most likely to be weaponized in ransomware attacks.