What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Deferred” does not mean a CVE was rejected, harmless, or invalid. NIST used it as an NVD enrichment workflow state for older vulnerabilities awaiting additional analysis. In its April 2026 operations update, NIST said records that had been marked Deferred in 2025 would be moved in batches to Modified After Enrichment. Separately, NIST said backlogged CVEs with NVD publication dates before March 1, 2026 would be placed in Not Scheduled under its new risk-based prioritization process. Those are different groups and different status changes.

What “Deferred” meant in the NVD

In April 2025, NIST said CVEs published before January 1, 2018 that were still waiting for enrichment would be marked Deferred. The age of those records meant NIST did not plan to prioritize updating their NVD enrichment at that time. NIST retained requests to update their metadata and said CVEs in CISA’s Known Exploited Vulnerabilities (KEV) catalog would be prioritized regardless of status.

Deferred was therefore an operational queue label. It was not a judgment that a vulnerability lacked impact, had been fixed, or should be ignored. The CVE remained a record in the NVD, where security teams and tools could still use the available data.

What NIST announced in April 2026

NIST’s April 15, 2026 operations update (updated April 17) addressed the growth of CVE submissions and changed how enrichment work would be prioritized.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

New prioritization criteria

Effective April 15, 2026, NIST said it would prioritize:

  • CVEs listed in CISA’s KEV catalog;
  • CVEs affecting software used within the federal government; and
  • CVEs affecting critical software defined by Executive Order 14028.

Other submitted CVEs still enter the NVD, but NIST categorizes them as Lowest Priority – not scheduled for immediate enrichment. NIST’s stated goal is to enrich KEV-listed CVEs within one business day of receipt; that is a service goal, not an unconditional guarantee.

Why the workflow changed

NIST reported a 263% increase in CVE submissions between 2020 and 2025. It said nearly 42,000 CVEs were enriched in 2025, 45% more than in any prior year. Submissions during the first three months of 2026 were also nearly one-third higher than during the same period in 2025. These figures explain the need to allocate limited enrichment capacity, but they do not change the meaning of an individual CVE’s severity or exploitability.

Two populations, two status changes

The most important distinction is between the older Deferred records and the broader backlog addressed by the 2026 prioritization rollout.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Population Original condition NIST’s announced destination What the change means
2025 Deferred records CVEs published before January 1, 2018 and awaiting enrichment Modified After Enrichment A status-handling transition for records already marked Deferred; it does not establish that every record received a fresh, full analysis.
Backlogged records CVEs with an NVD publication date earlier than March 1, 2026 that were in the backlog when the new criteria took effect Not Scheduled The records were moved into a queue state indicating that enrichment was not currently scheduled. KEV records were excluded from this backlog treatment.

NIST said the Deferred-to-Modified After Enrichment recategorization would be performed in batches over the following two weeks because of the volume. The announcement describes the planned process; it does not by itself confirm that every batch had completed.

How the NVD labels map to API statuses

The NVD’s status reference uses a display label and an API value:

  • Not Scheduled is the display label for API status Deferred. It means NVD enrichment is not currently scheduled. Scope, prioritization, available resources, or other concerns may account for the state, and a user can request scheduling.
  • Modified After Enrichment is the display label for API status Modified. It indicates that the record was changed after NVD enrichment.

Neither status is a severity rating. A record marked Not Scheduled has not been declared low risk, and a record marked Modified After Enrichment has not automatically been re-scored or revalidated in full.

Rejected is separate. Rejected CVE records are determined by the CVE Program and, according to NVD status guidance, should no longer be used. Do not treat Not Scheduled or Modified After Enrichment as equivalent to Rejected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “all submitted CVEs” means

NIST stated that “All submitted CVEs will still be added to the NVD.” Presence in the database and NVD enrichment are separate questions. A CVE can be searchable and available to downstream tools while lacking immediate NIST enrichment, or while waiting for a scheduling decision.

For a record with limited NVD enrichment, consult the CNA’s advisory, vendor security bulletin, affected-version information, remediation guidance, and other authoritative sources. NVD scheduling status tells you about NIST’s workflow; it does not replace product-specific evidence.

How security teams should assess a limited-enrichment CVE

1. Check KEV membership

KEV inclusion is NIST’s strongest stated prioritization signal because it represents known exploitation tracked by CISA. Treat membership as an urgent operational input, while remembering that absence from KEV is not proof that exploitation is impossible.

2. Match the affected software to your environment

Determine whether the vulnerable product, version, and configuration are actually deployed. NIST’s federal-government and critical-software criteria matter most when they overlap with your assets and mission.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Use vendor and CNA evidence

When NVD enrichment is delayed, obtain affected-version ranges, workarounds, patches, and exploit indicators from the submitting CNA or the vendor. Record the source and date in your vulnerability-management system.

4. Interpret the status correctly

Not Scheduled indicates a scheduling delay. Modified After Enrichment indicates a post-enrichment record change. Neither label supplies a risk score or a remediation deadline.

5. Request enrichment when it matters

NIST says users may request enrichment for lowest-priority records. Requests are reviewed and scheduled as resources allow, so a request should supplement—not delay—your own risk assessment and mitigation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Changes to NIST severity scoring

NIST said it would no longer routinely provide a separate NIST severity score when the submitting CVE Numbering Authority had already supplied one. A separate NIST score can still be requested for a specific CVE. As a result, some records may present the CNA’s score without a duplicate NIST score; that is a scoring-policy change, not evidence that the vulnerability became less serious.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens when an enriched record changes

NIST said it would reanalyze a CVE after enrichment only when it knew that a later modification materially affected the enrichment data. Users can request review of particular records. A modified record therefore signals that the underlying entry changed, but the status alone does not tell you whether the change affects affected versions, severity, exploitability, or remediation.

Limits of the prioritization model

NIST cautioned that its criteria may miss some potentially high-impact CVEs. Organizations should therefore continue using asset exposure, business criticality, exploit intelligence, vendor guidance, compensating controls, and local threat information rather than filtering solely by NVD status or by the presence of a NIST score.

Bottom line for vulnerability programs

Read the labels as workflow metadata. The older Deferred cohort was slated for a move to Modified After Enrichment, while a separate pre-March 1, 2026 backlog was slated for Not Scheduled. All submitted CVEs remain in the NVD, but not all receive immediate enrichment. Use KEV membership and asset impact to set urgency, verify details with authoritative vendor or CNA sources, and request NVD enrichment when additional analysis would materially improve a decision.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.