NIST's National Vulnerability Database announced that starting April 15, 2026, it will prioritize CVE enrichment (CVSS, CPE, CWE data) for only three categories: CISA's Known Exploited Vulnerabilities catalog, federal government software, and critical software under Executive Order 14028. Everything else becomes lowest priority for enrichment, though CVE issuance by CNAs continues unaffected. The piece explains the CVE pipeline (CNAs issue CVEs, NIST/NVD adds enrichment downstream), shows NVD enrichment peaked at 29,817 CVEs in 2024 but fell to 25,453 in 2025 even as reservations kept climbing, and points to CVE Record Format v5 and the Authorized Data Publisher role (currently only CISA's Vulnrichment) as partial fixes for the enrichment backlog. The recommendation for security teams is to adopt risk-based patch triage rather than relying solely on NIST enrichment, asking exploitability, exposure, and configuration questions to prioritize remediation.

12m read timeFrom bishopfox.com
Post cover image
Table of contents
What's whatPlease continue to patch!This means fewer CVEs for your security team, right... right?Where this leaves usWhat it costs the rest of usWhat you can do about it

Questions this post answers

What changed with NIST's NVD CVE enrichment as of April 15, 2026?

Starting April 15, 2026, NIST's National Vulnerability Database shifted from enriching CVEs on a rolling basis to a tiered priority model, focusing deeper enrichment (CVSS scores, CPE configurations, CWE classifications) on CVEs in CISA's Known Exploited Vulnerabilities catalog, federal government software, and critical software defined under Executive Order 14028. All other CVEs become lowest priority and may see little or no enrichment. Security teams adjusting patch workflows around this change can track vulnerability news on daily.dev.

Does NIST's new CVE enrichment prioritization mean fewer CVEs will be issued?

No, CVE issuance is unaffected because NIST is not a CVE Numbering Authority (CNA) and never issued CVE identifiers. CNAs like MITRE and over 500 partner organizations continue assigning CVEs; NIST only adds downstream enrichment data such as CVSS, CPE, and CWE information after a CVE is publicly released, and it is only that enrichment step being deprioritized for non-critical software. Developers tracking how CVE data flows through the ecosystem can follow updates like this on daily.dev.

How much did NIST's CVE enrichment output change between 2024 and 2025?

NIST-enriched CVEs peaked at 29,817 in 2024 and then fell to 25,453 in 2025, even as reserved CVEs kept climbing, with 40,077 new CVEs issued in 2024 and 48,244 in 2025. NIST's own figure for 2025 enrichment is cited as nearly 42,000, since it counts any CVE touched in any way, versus counting only detectable public enrichment artifacts like a primary CVSS score, CWE, or populated CPE data. Teams measuring vulnerability backlog trends can keep an eye on infrastructure security shifts via daily.dev.

1 Impression