CVEs as rain drops falling onto IT worker with umbrella

NIST Scales Back CVE Details to Manage Report Surge

NIST will narrow its focus on CVE analysis, prioritizing urgent vulnerabilities, amidst a surge in submissions and AI-generated reports.

A surge in vulnerability submissions is forcing the National Institute of Standards and Technology, the U.S. agency that helps maintain the National Vulnerability Database, to narrow how it handles Common Vulnerabilities and Exposures, or CVEs. Starting April 15, 2026, NIST said it will focus its added analysis on a smaller set of the most urgent flaws.

That added analysis, often called enrichment, gives security teams valuable information to prioritize patches. NIST has traditionally added items such as severity scores and affected product lists to all CVE records.

NIST said CVE submissions rose 263% between 2020 and 2025. “We are working faster than ever. We enriched nearly 42,000 CVEs in 2025 — 45% more than any prior year,” NIST wrote.

Cybersecurity professionals have reacted with a mix of concern and understanding. The move is risky because it removes context many teams use for triage. It will also force defenders to rely more on vendor advisories, CISA, CNAs and commercial tools rather than treat the NVD as a one-stop prioritization source, according to comments published by ITPro.

Now NIST will concentrate that work on three groups: vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog, software used by the federal government and “critical software” covered by Executive Order 14028. NIST said it aims to enrich KEV-listed flaws within one business day of receipt.

Executive Order 14028 is the 2021 White House cybersecurity order that pushed agencies and suppliers to improve software security and the software supply chain. NIST uses that order’s framework to identify software with broad security importance.

CVEs outside those categories will still appear in the NVD. But many will no longer get the extra NIST analysis teams often use to decide what to patch first. NIST did not set a public severity-score cutoff such as “only critical” or “only high.” Instead, it chose categories it believes carry the greatest potential for widespread impact.

CVEs that fall outside those buckets will be labeled “Not Scheduled,” which means NIST is not prioritizing them for immediate enrichment. Users can still ask NIST to review specific entries.

AI-generated CVE submissions and years of NIST expanding the number of organizations allowed to assign and publish CVE records are driving the uptick in submissions.

In 2016, the NIST program had 23 CVE Numbering Authorities, or CNAs. By March 31, 2026, it had 502 participating organizations from 42 countries. More CNAs means more direct reporting and more records entering the system.

The other factor is a spike in AI-generated submissions. GitHub’s Madison Ficorilli told RSAC 2026 attendees that vulnerability reports jumped 224% over one 90-day period compared with the previous 90 days at GitHub, according to a report by Cybersecurity Dive.

A VulnCon 2026 session description put it even more bluntly.

“The rise of large language models has fundamentally changed how vulnerability reports are written,” wrote Khushali Dalal, a product security engineer at Juniper Networks.

“As AI dramatically increases both the volume and perceived credibility of vulnerability submissions, PSIRT teams and vulnerability management teams are seeing a surge of submissions that are partially or entirely AI-generated — often polished, technically plausible and sometimes completely wrong.”

Total
0
Shares
Previous Article
Circuit board illustrating China and Russia potential abuse of Routers.

Router Ban? Netgear Says Not So Fast

Next Article
shards of saphire around a macOS and Apple logo illustrating the news Microsoft tracks Sapphire Sleet’s new macOS intrusion chain

Fake Zoom Update Targets macOS Users in Malware Campaign

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading