NIST's Cutback on Vulnerability Enrichment Sparks Concerns
New research finds thousands of CVEs left unanalyzed or inaccurately scored after NIST scaled back its National Vulnerability Database work.

Key points
- NIST reduced CVE enrichment in April 2023, prioritizing actively exploited flaws and federal-government products.
- Of 13,441 CVEs published between April 15 and June 15, only 6,759 received NIST enrichment, leaving 1,583 unanalyzed.
- Scoring conflicts between NIST and CVE Numbering Authorities are creating risk-assessment confusion.
- FedRAMP cloud providers are required to use NIST CVSS scores, making the gaps especially costly for them.
- NIST's most common error: rating attack complexity as low when Volerion found it to be high, in roughly a third of disagreements.
NIST began sharply cutting the number of CVEs it enriches in April 2023, citing a severe backlog of submitted vulnerabilities. The agency now prioritizes flaws under active exploitation or found in products used by the federal government. Everything else largely waits.
Cybersecurity startup Volerion analyzed all 13,441 CVEs accepted to the National Vulnerability Database (NVD) between April 15 and June 15. More than half, 8,342, were flagged by NIST for enrichment. Only 6,759 actually received it, leaving 1,583 published vulnerabilities with no additional analysis. Just 2,645 of those enriched CVEs also received a NIST CVSS (Common Vulnerability Scoring System) score, the numerical severity rating organizations use to decide what to patch first.
"They're also wrong on the conclusions a lot of times," Volerion co-founder Ruben Bos told Dark Reading.
How did the reduction in NIST's efforts affect the CVE system?
Timeliness suffered alongside coverage. The median time to analysis was around four days in May, but Volerion found significant numbers of CVEs listed as "Awaiting Analysis" each week, exempted entirely from those median figures. Bottlenecks worsened when submission volumes spiked. "[The enrichment process] can be very slow, depending on the time frame you measure," co-founder Karel Knibbe told Dark Reading. With vulnerability counts climbing, evidenced by Microsoft's record Patch Tuesday, NIST looks likely to fall further behind.
We covered the structural side of this problem on 5 June in our Inspector General report story, which found NIST severity scores matched independent assessments only 12% of the time.
Should you worry about CVE score accuracy?
For cloud service providers inside FedRAMP, reduced enrichment is more than inconvenient: the program requires them to use NIST's CVSS score for risk determinations. With fewer scores available, they fall back on scores from CVE Numbering Authorities (CNAs), organizations authorized to assign CVE identifiers. Over 500 CNAs now participate, and Bos says some inflate severity for bug-bounty purposes while vendors sometimes deflate scores for their own products. "Some CNAs are just rubbish because they don't understand [the vulnerability] on a technical level," he said.
NIST's own scores aren't clean either. CVE-2026-8856, a denial-of-service flaw in IBM HTTP Server 8.5 and 9.0, drew a critical 9.1 from NIST, a medium 7.7 from IBM, and a medium 4.4 from Volerion, whose analysts argued the flaw requires local access and high privileges. That spread isn't an outlier; it's a pattern.
The real watch item here isn't whether NIST catches up. It's whether organizations quietly start treating CNA scores as authoritative, without the independent check that made NVD worth consulting in the first place.



