What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Short answer: NIST has changed how it enriches records in the National Vulnerability Database (NVD), not how CVE identifiers are created or whether CVEs are listed. From April 15, 2026, NIST directs immediate enrichment toward vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, software used by the U.S. federal government, and “critical software” covered by Executive Order 14028. Other submitted CVEs remain in the NVD and may be enriched later, but some are labeled Lowest Priority – not scheduled for immediate enrichment.
What changed in the NVD on April 15, 2026?
Previously, NIST described the NVD as aiming to analyze every CVE and add information such as severity scores and affected-product data. The revised operation is a prioritization model for that enrichment work. It does not change the CVE identifier system, invalidate lower-priority records, or remove submitted vulnerabilities from the NVD.
NIST reported that CVE submissions rose 263% between 2020 and 2025, and that submissions in the first three months of 2026 were nearly one-third higher than during the same period in 2025. It said the NVD enriched nearly 42,000 CVEs in 2025, 45% more than in any previous year. These figures are NIST’s explanation for the operational change; they do not quantify the effect on any particular organization’s risk.
Which vulnerabilities does NIST prioritize in the NVD?
| Priority signal | What it means | NIST’s stated handling |
|---|---|---|
| CISA KEV Catalog | The vulnerability is listed by CISA as known to be exploited in the wild. | NIST says its goal is to enrich these CVEs within one business day of receipt. |
| Federal-government software | The affected software is used within the U.S. federal government. | Included in NIST’s priority enrichment categories; no universal turnaround is stated. |
| Critical software under Executive Order 14028 | The software falls within NIST’s EO 14028 definition, which includes categories such as operating systems, hypervisors, container environments, and vulnerability-detection and management software. | Included in the priority categories; timing depends on NVD capacity and workflow. |
The categories are signals for allocating NIST enrichment effort. They are not a complete definition of high impact. NIST explicitly cautions that its criteria may not catch every potentially high-impact CVE.
#1 Best Overall
What happens if a CVE isn’t enriched by NIST?
The CVE is still listed
NIST states, “All submitted CVEs will still be added to the NVD.” A record can therefore be present in the database even when NIST has not yet added its own analysis, affected-product normalization, or other enrichment.
It may show “Not Scheduled”
Records outside the immediate priority groups may receive the status Lowest Priority – not scheduled for immediate enrichment. “Not scheduled” describes the timing of NIST’s work; it does not mean that the CVE is absent, fraudulent, harmless, or permanently excluded.
Enrichment can still occur later
NIST says lower-priority records may be considered for future enrichment as resources allow. It also allows users to request enrichment for a specific record. NIST reviews those requests and schedules work according to available resources, so a request is not a guaranteed escalation or service-level commitment.
How the backlog is being handled
NIST says the backlog of unenriched CVEs began growing in early 2024. Under the transition, backlogged CVEs with an NVD publication date before March 1, 2026 move into Not Scheduled. They can still be considered under the new criteria. NIST says the backlog does not include CVEs in CISA’s KEV Catalog, which it has continued to prioritize.
Rank #2
What changed about severity scores and modified records?
NIST scores are no longer routine duplicates
When a CVE Numbering Authority (CNA) has already supplied a severity score, NIST will no longer routinely add a separate NIST score. Users can request a NIST score for an individual record. A CNA-provided score and NIST enrichment are therefore different data sources and should not be treated as interchangeable fields.
Modified records are reanalyzed when material
After enrichment, NIST says it will reanalyze a record when it becomes aware of a modification that materially affects enrichment data. It will not automatically reanalyze every modified CVE.
How to interpret an NVD record after the change
| Question | What the record can tell you | What it cannot establish by itself |
|---|---|---|
| Is the CVE listed? | Whether the submitted CVE appears in the NVD. | That NIST has completed enrichment. |
| Is it enriched? | Whether NIST has added the relevant analysis and product data available for that record. | That the vulnerability is safe if enrichment is absent. |
| Who supplied the severity? | Whether a CNA or NIST supplied a score. | That two scores from different sources have identical methods or meaning. |
| Does it have SSVC or product data? | Whether those data elements are present in the current feed or API response. | That their presence changes the NIST prioritization category. |
Assess exposure using the affected product, version, deployment, exploit evidence, compensating controls, and business context. An unenriched or not-scheduled record needs independent review rather than automatic downgrading.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Related NVD feed and API changes in 2026
NIST’s later data-delivery updates are separate from the April prioritization policy.
Rank #3
June 17, 2026: SSVC and affected-product data
The NVD status page says the NVD deployed CISA-Authorized Data Publisher Stakeholder-Specific Vulnerability Categorization (SSVC) information and affected-product information from CVE records to its feeds and APIs.
August 26, 2026: audit-history links
NIST changed audit-history entries so they link to the CVE record in GitHub instead of embedding the full affected-data JSON payload in every history entry. The current CVE detail endpoint continues to return the latest full affected JSON. This is a schema and delivery change, not a new priority rule.
What organizations should change in their vulnerability workflow
Use KEV as an urgency signal, not as the only watchlist
Track CISA KEV status and apply your own exposure and business-impact rules. NIST’s one-business-day enrichment goal applies to KEV CVEs as a stated objective, not as a promise that every other NVD field will be complete within that period.
Recommended Free Tools
Do not filter out “Not Scheduled” records
Keep those CVEs in ingestion, triage, and reporting pipelines. Use CNA data, vendor advisories, affected-product evidence, exploit intelligence, and internal asset data while waiting for possible NIST enrichment.
Rank #4
Record data provenance
Store whether severity came from a CNA or NIST, and distinguish NVD enrichment from CISA-ADP SSVC information. This prevents a missing NIST score from being mistaken for a missing vulnerability assessment.
Request enrichment when the record matters to you
Contact the NVD program with the CVE and the operational reason it matters. NIST says it will review requests and schedule work as resources allow; organizations should continue their own assessment rather than wait for a promised response time.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What NIST’s modernization discussion does—and does not—mean
In an August 12, 2026 blog post, NIST authors Harold Booth and Jon Boyens requested feedback on vulnerability-management processes, information dissemination, risk assessment and prioritization, remediation, vulnerability data and standards, development processes, and the NVD’s future. They use the phrase “continuous, automated, and contextual vulnerability management” to frame that modernization effort.
Free tools Windows power users keep installed
One-click scans. No signup required.
That post is a request for input, not evidence that a proposed future automated capability has already been deployed. The April enrichment policy and the June and August feed changes are the operational facts currently described by NIST.
Best Value
Practical answers to the main reader questions
Does “Not Scheduled” mean the CVE is not in the NVD?
No. NIST says all submitted CVEs continue to be added. The label concerns immediate enrichment, not listing.
Does a missing NIST enrichment mean the vulnerability is low risk?
No. NIST warns that its criteria may miss potentially high-impact vulnerabilities, and the reviewed policy does not establish that an unenriched CVE is safe.
Will every requested CVE be enriched quickly?
No turnaround is guaranteed. NIST says it reviews requests and schedules work as resources allow.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchDoes the April policy change the CVE numbering system?
No. It changes NVD enrichment priorities, not CVE assignment or the continued addition of submitted records.
Bottom line for security teams
Treat the 2026 change as a change in NIST’s enrichment queue. Prioritize KEV entries, federal-use software, and EO 14028 critical software, but continue evaluating every CVE that affects your assets. A CVE can be valid and present in the NVD while awaiting enrichment, and “Not Scheduled” is a workload status—not a risk rating.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

