A Department of Commerce Office of Inspector General audit found that NIST mismanaged the National Vulnerability Database (NVD), allowing a backlog of unprocessed vulnerabilities to surge from about 13,000 in 2024 to more than 27,000 by the end of 2025 after a key enrichment support contract lapsed in February 2024. Auditors said NIST had years of notice before the contract expired but failed to prepare adequately, leaving the program understaffed and causing vulnerability processing to nearly halt. The report also said NIST missed its own recovery goals, lacked a strategic plan, and communicated poorly with stakeholders, undermining confidence in one of the federal government’s most widely used vulnerability resources.
The audit said delays were worsened by inefficient enrichment workflows, heavy time spent on CVSS scoring, and duplicated effort with CISA’s Vulnrichment program in roughly 21,000 cases, wasting an estimated $200,000. Auditors found NIST was slow to incorporate CISA data, did not consistently prioritize the most critical flaws, and could save about $800,000 over two years by relying more on vendor-provided severity scores. NIST agreed with the recommendations and said it would adopt operational improvements, including a more risk-based approach that prioritizes high-impact CVEs and greater use of scores supplied by CVE Numbering Authorities, though it disputed parts of the auditors’ characterization and said statutory requirements were not fully considered.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Following the inspector general's report, NIST was required to submit a formal remediation or action plan by late July 2026, with one report specifying a deadline of July 25, 2026.
NIST announced a new approach for the NVD that prioritizes enrichment for the most critical CVEs and relies more on severity scores supplied by CVE Numbering Authorities rather than producing comprehensive entries for every CVE.
A Department of Commerce Office of Inspector General report found that NIST mismanaged the National Vulnerability Database through poor planning, inefficient processes, weak communication, and overlap with CISA, and issued six recommendations for remediation. NIST agreed with the recommendations while disputing parts of the characterization.
Between May 2024 and December 2025, auditors found roughly 21,000 cases where NIST duplicated vulnerability enrichment work already performed by CISA's Vulnrichment program, wasting resources and slowing operations.
By the end of 2025, the number of unprocessed vulnerabilities in the National Vulnerability Database had grown to more than 27,000, according to the inspector general's findings.
A replacement contract for NVD enrichment support was finally established by late November 2024 after months of understaffing and delayed funding action.
NIST had publicly pledged to eliminate the NVD backlog by September 2024, but the inspector general later found the agency failed to meet that target.
By June 2024, the backlog of unprocessed vulnerabilities in the National Vulnerability Database had grown to roughly 13,000 following the contract lapse and processing slowdown.
NIST's private-sector enrichment support contract expired in February 2024, leaving the National Vulnerability Database understaffed and contributing to a sharp slowdown in vulnerability processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
itif.org
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehelpnetsecurity.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceoig.doc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.