As cited
Copy frozen at (site build).
vulnerabilities
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals
NIST's National Vulnerability Database changed its enrichment policy on April 15, 2026 to prioritize only CVEs appearing in the CISA Known Exploited Vulnerabilities catalog, federal software, or software designated critical under Executive Order 14028, marking roughly 15-20% of anticipated CVE volume while leaving the remainder unenriched without CVSS scores or product mappings. Vulnerability management teams that depend on NVD CVSS scores may face operational gaps as the backlog grows. Recorded Future argues that effective vulnerability prioritization should rely on attacker behavior signals and the weaponization lifecycle rather than institutional CVSS scoring delays.
Why it matters: Security teams using CVSS scores from NVD as primary vulnerability prioritization inputs will lose enrichment data on 80-85% of incoming CVEs, requiring alternative risk scoring methods that track exploit availability, proof-of-concept development, and active attacker use to maintain effective patch prioritization.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals
NIST's National Vulnerability Database changed its enrichment policy on April 15, 2026 to prioritize only CVEs appearing in the CISA Known Exploited Vulnerabilities catalog, federal software, or software designated critical under Executive Order 14028, marking roughly 15-20% of anticipated CVE volume while leaving the remainder unenriched without CVSS scores or product mappings. Vulnerability management teams that depend on NVD CVSS scores may face operational gaps as the backlog grows. Recorded Future argues that effective vulnerability prioritization should rely on attacker behavior signals and the weaponization lifecycle rather than institutional CVSS scoring delays.
Why it matters: Security teams using CVSS scores from NVD as primary vulnerability prioritization inputs will lose enrichment data on 80-85% of incoming CVEs, requiring alternative risk scoring methods that track exploit availability, proof-of-concept development, and active attacker use to maintain effective patch prioritization.
- Source published
- First seen by Cybersecurity Tracker