Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsThe NVD backlog reflects a widening gap between the number of CVEs submitted and NIST’s capacity to add detailed enrichment. Since April 15, 2026, NIST has continued adding CVEs to the National Vulnerability Database (NVD) while prioritizing enrichment for vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, software used by the federal government, and critical software defined under Executive Order 14028. A CVE can therefore be in the NVD without being fully enriched or scheduled for immediate enrichment.
Why the NVD backlog keeps growing
NIST reported that CVE submissions rose 263% from 2020 to 2025. Submissions in the first three months of 2026 were nearly one-third higher than in the same period of 2025. NIST also said it enriched nearly 42,000 CVEs in 2025—45% more than in any prior year—but that output still did not keep pace with incoming records. These figures come from NIST’s April 15, 2026 announcement.
The problem had already been visible in 2025. In a March 19, 2025 update, NIST said the backlog continued to grow after CVE submissions increased 32% in 2024 and the previous processing rate proved insufficient. The 2026 figures show the mismatch persisted despite higher enrichment output.
What NIST changed in April 2026
Beginning April 15, NIST adopted a risk-based approach to deciding which records receive enrichment first. The change concerns enrichment priority and queue handling—not whether CVEs are added to the NVD.
#1 Best Overall
Records prioritized for enrichment
- CVEs listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
- CVEs affecting software used within the federal government.
- CVEs affecting critical software as defined by Executive Order 14028.
NIST’s stated goal is to enrich KEV-listed CVEs within one business day of receipt. It cautioned that “These criteria may not catch every potentially high-impact CVE.”
What happens to other records
CVEs outside the priority groups may be marked “Lowest Priority – not scheduled for immediate enrichment.” NIST said it would move backlogged CVEs with an NVD publish date before March 1, 2026, to “Not Scheduled.” The agency may enrich those records later as resources allow. NIST said KEV Catalog CVEs were not part of this backlog because it had continued to prioritize them.
“Not Scheduled” does not mean a vulnerability record has been removed from the NVD or that it will never be enriched. It indicates that immediate NIST enrichment is not scheduled.
Scoring and reanalysis also changed
NIST said it would stop routinely adding a separate NIST severity score when the CVE Numbering Authority (CNA) that submitted a CVE has already supplied one. Users can request a separate NIST score for a particular CVE. NIST also said it would reanalyze modified, enriched CVEs when it knows a change materially affects enrichment, rather than automatically reanalyzing every modified record. Users can request a review.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
How to assess a CVE when NVD enrichment is incomplete
For security decisions, treat NVD enrichment as one input—not as a complete verdict on whether a vulnerability is dangerous or how urgently it needs attention. A missing NIST score or product mapping is not proof that a CVE is harmless.
- Check the NVD record and its status. Confirm whether the CVE is listed and whether its NIST enrichment is complete, pending, or marked “Not Scheduled.” Presence in the database and completion of enrichment are separate things.
- Check CISA KEV. KEV listing is evidence of known exploitation and is one of NIST’s stated enrichment priorities.
- Verify affected versions and fixes with the vendor. Use the vendor’s advisory and affected-version details to establish whether your installed software is affected and what remediation is available.
- Apply your organization’s context. Consider whether the software is in your inventory, its exposure and business importance, evidence of exploitation, and available remediation. Compare those factors alongside—not in place of—the NVD status.
If a lower-priority CVE merits NIST enrichment or a separate NIST severity score, NIST says users may email a request. A request does not guarantee a schedule; any work remains subject to available resources.
Rank #4
Oversight and modernization have not established that the backlog is cleared
A Commerce Department Office of Inspector General public summary for evaluation OIG-26-020-I, issued May 26, 2026, says NIST management of the NVD had not been sufficient to resolve the unprocessed-vulnerability backlog or keep pace with submission growth. The detailed report is marked secured on the public page, so the public summary does not establish further specifics about causes, staffing, costs, or recommendations.
NIST’s June 2026 technical update added Stakeholder-Specific Vulnerability Categorization (SSVC) information from the CISA-Authorized Data Publisher and “affected” software information from CVE records. NIST said the process affected approximately 95% of existing vulnerabilities, updating their change logs and last-modified timestamps and temporarily enlarging the modified feed. That figure describes records touched during a schema expansion; it is not the share of the backlog resolved or the share fully enriched. Details appear in NIST’s NVD technical updates.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
In September 2026, NIST described early work on an AI-agent enrichment workflow. Its event description, updated September 25, 2026, outlined goals that include scalability, automation, interoperability, transparency, and utility. It did not quantify a backlog reduction or say the workflow had been deployed across the NVD. NIST described the underlying challenge this way: “The increasing scale and complexity of discovered vulnerabilities poses a challenge for the NVD to provide timely information that is actionable to users of NVD data.”
Is there a current NVD backlog count?
The official sources cited here do not establish a verified current count of unprocessed, “Not Scheduled,” or otherwise unenriched records. NIST points users to a real-time dashboard, but a current, validated total is not available in these published figures. Avoid treating an older or undated tally as the present backlog size.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

