NIST is reevaluating its role in analyzing and “enriching” vulnerabilities in the National Vulnerability Database (NVD) as demand for vulnerability analysis continues to outpace the agency’s capacity. NIST leadership told the Information Security and Privacy Advisory Board that the enrichment process is labor-intensive and “not scalable” given the volume of incoming CVEs, prompting a strategic review and a shift toward prioritizing/triaging which vulnerabilities receive deeper analysis.
The broader ecosystem is also seeing parallel efforts to improve vulnerability correlation and disclosure workflows outside of any single identifier system. Vulnerability-Lookup is positioned as a sharing and correlation platform that aggregates vulnerability information from multiple sources, supports sightings (e.g., seen, exploited, patched), and is designed to operate independently of specific vulnerability IDs while remaining compatible with the Global CVE Allocation System (GCVE)—highlighting how tooling and processes are evolving as stakeholders question scalability and governance of centralized vulnerability analysis.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
NIST said it is coordinating with CISA over possible duplication with the Vulnrichment project and engaging with Europe's GCVE initiative to reduce fragmentation in vulnerability data efforts. A Commerce Department inspector general audit of the NVD was also noted as ongoing.
As part of its reassessment, NIST said it plans to publish a strategy and implementation plan, hire a program manager if authorized, and consult stakeholders on which NVD data is most useful. It also said it wants to eventually shift more enrichment responsibility to CVE Numbering Authorities after issuing guidance.
NIST said it will formalize which vulnerabilities receive enrichment, prioritizing items such as those in CISA's Known Exploited Vulnerabilities catalog and software relevant to federal agencies or critical systems. The move is intended to focus limited resources on the most consequential CVEs.
Acting Computer Security Division chief Jon Boyens said NIST has been unable to keep up with the volume of incoming CVEs, describing the current enrichment process as labor-intensive and not scalable. NIST also signaled it does not intend to enrich every CVE submission.
NIST launched a strategic review of the NVD as demand for vulnerability analysis increased and scrutiny grew over the U.S. government's role in the CVE/NVD ecosystem. The review is examining how NIST should prioritize and deliver vulnerability enrichment going forward.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.