NIST Shifts the NVD to a Risk-Based Model Under CVE Pressure

NIST is overhauling operations for the National Vulnerability Database as record-breaking CVE growth strains its ability to enrich every submission. With CVE volume up 263% between 2020 and 2025—and 2026 already trending higher—the agency is prioritizing detailed analysis for actively exploited flaws, federal systems, and critical software. The move marks a structural shift from universal coverage to risk-based triage, signaling that organizations must rely on broader intelligence sources rather than treating NVD enrichment as a complete vulnerability strategy.

https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

SecObserve: Simplified Vulnerability and License Management for CI/CD Pipelines

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know