Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The NVD backlog reflects a widening gap between the number of CVEs submitted and NIST’s capacity to add detailed enrichment. Since April 15, 2026, NIST has continued adding CVEs to the National Vulnerability Database (NVD) while prioritizing enrichment for vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, software used by the federal government, and critical software defined under Executive Order 14028. A CVE can therefore be in the NVD without being fully enriched or scheduled for immediate enrichment.

Why the NVD backlog keeps growing

NIST reported that CVE submissions rose 263% from 2020 to 2025. Submissions in the first three months of 2026 were nearly one-third higher than in the same period of 2025. NIST also said it enriched nearly 42,000 CVEs in 2025—45% more than in any prior year—but that output still did not keep pace with incoming records. These figures come from NIST’s April 15, 2026 announcement.

The problem had already been visible in 2025. In a March 19, 2025 update, NIST said the backlog continued to grow after CVE submissions increased 32% in 2024 and the previous processing rate proved insufficient. The 2026 figures show the mismatch persisted despite higher enrichment output.

What NIST changed in April 2026

Beginning April 15, NIST adopted a risk-based approach to deciding which records receive enrichment first. The change concerns enrichment priority and queue handling—not whether CVEs are added to the NVD.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Records prioritized for enrichment

  • CVEs listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
  • CVEs affecting software used within the federal government.
  • CVEs affecting critical software as defined by Executive Order 14028.

NIST’s stated goal is to enrich KEV-listed CVEs within one business day of receipt. It cautioned that “These criteria may not catch every potentially high-impact CVE.”

What happens to other records

CVEs outside the priority groups may be marked “Lowest Priority – not scheduled for immediate enrichment.” NIST said it would move backlogged CVEs with an NVD publish date before March 1, 2026, to “Not Scheduled.” The agency may enrich those records later as resources allow. NIST said KEV Catalog CVEs were not part of this backlog because it had continued to prioritize them.

“Not Scheduled” does not mean a vulnerability record has been removed from the NVD or that it will never be enriched. It indicates that immediate NIST enrichment is not scheduled.

Scoring and reanalysis also changed

NIST said it would stop routinely adding a separate NIST severity score when the CVE Numbering Authority (CNA) that submitted a CVE has already supplied one. Users can request a separate NIST score for a particular CVE. NIST also said it would reanalyze modified, enriched CVEs when it knows a change materially affects enrichment, rather than automatically reanalyzing every modified record. Users can request a review.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to assess a CVE when NVD enrichment is incomplete

For security decisions, treat NVD enrichment as one input—not as a complete verdict on whether a vulnerability is dangerous or how urgently it needs attention. A missing NIST score or product mapping is not proof that a CVE is harmless.

  1. Check the NVD record and its status. Confirm whether the CVE is listed and whether its NIST enrichment is complete, pending, or marked “Not Scheduled.” Presence in the database and completion of enrichment are separate things.
  2. Check CISA KEV. KEV listing is evidence of known exploitation and is one of NIST’s stated enrichment priorities.
  3. Verify affected versions and fixes with the vendor. Use the vendor’s advisory and affected-version details to establish whether your installed software is affected and what remediation is available.
  4. Apply your organization’s context. Consider whether the software is in your inventory, its exposure and business importance, evidence of exploitation, and available remediation. Compare those factors alongside—not in place of—the NVD status.

If a lower-priority CVE merits NIST enrichment or a separate NIST severity score, NIST says users may email a request. A request does not guarantee a schedule; any work remains subject to available resources.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Oversight and modernization have not established that the backlog is cleared

A Commerce Department Office of Inspector General public summary for evaluation OIG-26-020-I, issued May 26, 2026, says NIST management of the NVD had not been sufficient to resolve the unprocessed-vulnerability backlog or keep pace with submission growth. The detailed report is marked secured on the public page, so the public summary does not establish further specifics about causes, staffing, costs, or recommendations.

NIST’s June 2026 technical update added Stakeholder-Specific Vulnerability Categorization (SSVC) information from the CISA-Authorized Data Publisher and “affected” software information from CVE records. NIST said the process affected approximately 95% of existing vulnerabilities, updating their change logs and last-modified timestamps and temporarily enlarging the modified feed. That figure describes records touched during a schema expansion; it is not the share of the backlog resolved or the share fully enriched. Details appear in NIST’s NVD technical updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In September 2026, NIST described early work on an AI-agent enrichment workflow. Its event description, updated September 25, 2026, outlined goals that include scalability, automation, interoperability, transparency, and utility. It did not quantify a backlog reduction or say the workflow had been deployed across the NVD. NIST described the underlying challenge this way: “The increasing scale and complexity of discovered vulnerabilities poses a challenge for the NVD to provide timely information that is actionable to users of NVD data.”

Is there a current NVD backlog count?

The official sources cited here do not establish a verified current count of unprocessed, “Not Scheduled,” or otherwise unenriched records. NIST points users to a real-time dashboard, but a current, validated total is not available in these published figures. Avoid treating an older or undated tally as the present backlog size.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.