NIST's NVD now enriches only CVEs in the CISA Known Exploited Vulnerabilities catalog, federal software, or EO 14028-critical software — leaving roughly 80–85% of new CVEs without CVSS scores, product mappings, or weakness classifications. This creates an operational gap for teams relying on NVD-sourced CVSS scores for patch prioritization. Recorded Future argues CVSS was never designed for prioritization and that real risk signals come from attacker behavior: exploit code on GitHub, ransomware operator activity, malware samples, and underground forum discussions. Their vulnerability risk scoring model weighs active exploitation evidence, proof-of-concept availability, and threat actor targeting independently of NVD enrichment. CVSS scores from CNAs still feed into the model, but divergence rates between CNA and NVD scores exceeded 70% in 2023, limiting their reliability. The recommendation is to audit prioritization signal sources and supplement or replace NVD-dependent workflows with intelligence grounded in observable attacker behavior.

5m read timeFrom recordedfuture.com
Post cover image
Table of contents
Where vulnerability risk actually originatesWhat the model actually weighs