Cybersecurity

NVD Gives Up on CVE Backlog as AI Inflow Accelerates

NIST now enriches only KEV, federal and critical-software CVEs; the pre-March 2026 backlog is 'Not Scheduled'. CVE submissions rose 263% from 2020 to 2025.

NVD Gives Up on CVE Backlog as AI Inflow Accelerates — article cover

In mid-April, NIST made the largest operational about-face in the National Vulnerability Database’s history: it will no longer promise to enrich every CVE — enrichment meaning the added severity scores, affected-product lists, and other analysis data — and will process only three high-priority classes instead. All backlogged CVEs published before March 1, 2026 were relabeled “Not Scheduled.” Researchers first spotted the NVD status-field changes around April 13–14, and NIST followed with the formal announcement, “NIST Updates NVD Operations to Address Record CVE Growth,” on April 15.

This is not a routine adjustment. Vulnerability pipelines worldwide — scanners, SBOM tooling, SOC playbooks — have long treated NVD as the default source for severity and affected scope. Giving up on enrichment is a formal service-level downgrade of a piece of public infrastructure.

The New Priority Order: Three Classes Only

Under the new criteria, NVD enriches just three classes immediately: CVEs in CISA’s Known Exploited Vulnerabilities (KEV) catalog, targeted within one business day of receipt; CVEs for software used within the federal government; and CVEs for “critical software” as defined by Executive Order 14028. Everything else is labeled “Lowest Priority - not scheduled for immediate enrichment,” and consumers can email NIST to request work on a specific CVE. Another structural change: when the submitting CVE Numbering Authority (CNA) has already provided a severity score, NIST will stop routinely duplicating it.

The announcement also reworks status labels and the surrounding tooling: CVEs marked “Deferred” in 2025 move to “Modified After Enrichment” in batches over two weeks; already-enriched CVEs are re-analyzed only when a modification materially affects enrichment data; and the NVD Dashboard now shows pending volume in real time. In other words, NIST is not pretending the backlog will disappear — it rewrote the definition of what counts as pending.

How the Backlog Piled Up to 27,000

NVD’s enrichment backlog has worsened since early 2024: roughly 13,000 unanalyzed CVEs in mid-2024, 18,358 by September 2024 (72.4% of that period’s new CVEs went unanalyzed), 25,000 by March 2025, and more than 27,000 by the end of 2025. NIST’s own announcement is equally blunt: CVE submissions grew 263% between 2020 and 2025; the first three months of 2026 ran nearly one-third above the same period last year; and the ~42,000 CVEs enriched in 2025 were 45% more than any prior year. A record-breaking pipeline, still falling behind.

The structural view is starker. By Project Discovery’s count, 2018–2021 produced roughly 77,000 CVEs over four years; 2022–2025 produced about 146,000 — nearly double. High-severity findings more than doubled too, from about 7,400 to about 15,900. At that point the quantity changes the nature of the problem.

AI Bent the Vulnerability Curve

Project Discovery’s analysis makes the causal story clearest. Annual CVE output held flat at 18k–21k from 2018 through 2021, then jumped two years running (+32% from 2023 to 2024, +23% from 2024 to 2025), hitting 49,458 in 2025 — a timeline that overlaps the reasoning-model and agentic-coding wave. The attack side accelerated in parallel: AI systems reportedly produce working exploits in roughly 10–15 minutes at $1–3 per attempt; the CVE-Genie research framework reproduced 51% of 2024–2025 CVEs with verified exploits at an average cost of $2.77; and separate experiments showed GPT-4 exploiting 87% of tested CVEs from the description alone. In-the-wild zero-days climbed from 20–30 per year before 2021 to 60–100 since. Mandiant’s measured time-to-exploit has compressed from 63 days in 2018 to single digits, even negative, in recent periods. A human-paced pipeline meeting machine-paced output ends exactly here: a policy surrender.

Impact on Scanners and Patch Pipelines

The practical fallout has three layers. First, severity and product-mapping data will increasingly be absent: teams that rank patches by NVD scores need to shift to a blend of original CNA scores, EPSS, KEV, and vendor advisories — and with NIST no longer duplicating scores, the quality of CNA self-reporting now directly determines downstream prioritization quality. Second, “not enriched by NVD” does not mean “not dangerous”: the tens of thousands of CVEs now marked Not Scheduled have lost official analysis, not real risk, so tracking logic has to be built in-house. Third, assumptions about patch windows need rewriting: when exploitation velocity is measured in hours, 90-day disclosure norms and quarterly patch cycles must compress too.

This is precisely the concrete case behind the “security engineering gets rebuilt under AI-driven output pressure” thread in the 2026 opening outlook (see the 2026 AI opening outlook). The NVD downgrade is not an endpoint — it hands vulnerability management responsibility back from a public facility to every engineering team individually.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL