CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1959

As cited

Copy frozen at (site build).

vulnerabilities

NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals

NIST's National Vulnerability Database changed its enrichment policy on April 15, 2026 to prioritize only CVEs appearing in the CISA Known Exploited Vulnerabilities catalog, federal software, or software designated critical under Executive Order 14028, marking roughly 15-20% of anticipated CVE volume while leaving the remainder unenriched without CVSS scores or product mappings. Vulnerability management teams that depend on NVD CVSS scores may face operational gaps as the backlog grows. Recorded Future argues that effective vulnerability prioritization should rely on attacker behavior signals and the weaponization lifecycle rather than institutional CVSS scoring delays.

Why it matters: Security teams using CVSS scores from NVD as primary vulnerability prioritization inputs will lose enrichment data on 80-85% of incoming CVEs, requiring alternative risk scoring methods that track exploit availability, proof-of-concept development, and active attacker use to maintain effective patch prioritization.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals

NIST's National Vulnerability Database changed its enrichment policy on April 15, 2026 to prioritize only CVEs appearing in the CISA Known Exploited Vulnerabilities catalog, federal software, or software designated critical under Executive Order 14028, marking roughly 15-20% of anticipated CVE volume while leaving the remainder unenriched without CVSS scores or product mappings. Vulnerability management teams that depend on NVD CVSS scores may face operational gaps as the backlog grows. Recorded Future argues that effective vulnerability prioritization should rely on attacker behavior signals and the weaponization lifecycle rather than institutional CVSS scoring delays.

Why it matters: Security teams using CVSS scores from NVD as primary vulnerability prioritization inputs will lose enrichment data on 80-85% of incoming CVEs, requiring alternative risk scoring methods that track exploit availability, proof-of-concept development, and active attacker use to maintain effective patch prioritization.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary