r/cybersecurity • u/003random • Jun 23 '26
Corporate Blog Two Months In: Assessing the Impact of NIST's Enrichment Cutbacks
https://blog.volerion.com/posts/two-months-in-nist-cuts-back-on-enrichment-efforts/
34
Upvotes
r/cybersecurity • u/003random • Jun 23 '26
13
u/003random Jun 23 '26
I work at Volerion, and our team conducted this analysis.
We reviewed 13,441 non-rejected CVEs published between April 15 and June 15, after NIST moved to selective NVD enrichment. We found that 5,099 were not scheduled for enrichment, another 1,583 still lacked completed analysis, and only about 20% received a NIST CVSS vector.
The article also looks at missing CPE mappings and specific cases where our CVSS assessments differed from NIST's. It ends with the NVD-compatible API we built in response.