---
title: "NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals"
url: https://daily.dev/posts/nist-nvd-enrichment-policy-change-prioritizing-vulnerabilities-with-attacker-behavior-signals-al3upgzlt
source_url: https://www.recordedfuture.com/blog/nist-nvd-enrichment
type: article
source: "Recorded Future Blog"
published: 2026-05-31T07:44:12.302Z
updated: 2026-05-31T08:10:01.419Z
tags: ["security"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals

**[Recorded Future Blog](https://daily.dev/sources/recorded-future-blog)** · 5 min read · 0 upvotes · 0 comments

## Summary

NIST's NVD now enriches only CVEs in the CISA Known Exploited Vulnerabilities catalog, federal software, or EO 14028-critical software — leaving roughly 80–85% of new CVEs without CVSS scores, product mappings, or weakness classifications. This creates an operational gap for teams relying on NVD-sourced CVSS scores for patch prioritization. Recorded Future argues CVSS was never designed for prioritization and that real risk signals come from attacker behavior: exploit code on GitHub, ransomware operator activity, malware samples, and underground forum discussions. Their vulnerability risk scoring model weighs active exploitation evidence, proof-of-concept availability, and threat actor targeting independently of NVD enrichment. CVSS scores from CNAs still feed into the model, but divergence rates between CNA and NVD scores exceeded 70% in 2023, limiting their reliability. The recommendation is to audit prioritization signal sources and supplement or replace NVD-dependent workflows with intelligence grounded in observable attacker behavior.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.recordedfuture.com/blog/nist-nvd-enrichment>

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/nist-nvd-enrichment-policy-change-prioritizing-vulnerabilities-with-attacker-behavior-signals-al3upgzlt)
