The NVD enrichment backlog is now a structural problem for enterprise security teams, not a temporary blip. On 15 April 2026, NIST announced a significant overhaul of how it manages vulnerability enrichment in the National Vulnerability Database, moving nearly 300,000 CVEs published before 1 March 2026 into a status labelled “Not Scheduled,” according to Semgrep. The backlog is not the result of negligence; it is the product of volume that the original model was never designed to absorb.
Why the NVD Enrichment Backlog Got This Large
The numbers behind the decision are stark. According to the Cloud Security Alliance, CVE submissions grew by 263% between 2020 and 2025, a pace that no enrichment pipeline built for the previous decade’s threat landscape was ever going to keep up with comfortably. The consequence is a database that has had to make hard editorial choices about which vulnerabilities receive the structured metadata, severity scoring, and affected-platform information that defenders actually use.
NIST’s response to that pressure is to concentrate enrichment where it matters most. From 15 April 2026, the agency is prioritising CVEs that appear in CISA’s Known Exploited Vulnerabilities (KEV) Catalogue, with a stated goal of enriching those entries within one business day of receipt. That is a sensible triage decision on its face, but as Recorded Future notes, the prioritised categories are expected to cover only 15 to 20% of anticipated CVE volume going forward. The remaining 80 to 85% sits in a queue with no defined timeline.
Meanwhile, the volume of new disclosures keeps climbing. Action1’s 2026 Software Vulnerability Ratings Report found that disclosed vulnerabilities across the enterprise software categories it analysed increased 92% in 2025 compared with 2024. Critical and high-severity vulnerabilities each rose 103%, and vulnerabilities enabling remote code execution increased 128%. Enterprise application exploitation, the report found, surged 800% in the same period. The NVD enrichment backlog is not getting smaller any time soon.
The Asymmetry That Puts Defenders at a Disadvantage
Gene Moody, Field CTO at Action1, frames the core risk clearly: the backlog creates an information asymmetry that works against defenders and, implicitly, for attackers. Security teams that rely on NVD as a normalised, authoritative source will encounter incomplete or delayed data on a growing proportion of CVEs. Attackers, by contrast, do not wait for structured enrichment before correlating vendor advisories, security research, patch releases, and public exploit information. They work from the same raw inputs defenders have, but without the dependency on a curated pipeline.
Enrichment is not cosmetic detail. The structured metadata that NVD provides, including affected-platform information, configuration context, and CVSS severity scoring, is what allows a security team to determine whether a given vulnerability actually applies to software running in their environment. Without it, the choice is either to wait for context that may not arrive promptly, or to make remediation decisions from fragmented intelligence. Neither option is comfortable when exploitation can move faster than internal validation processes.
There is also a compounding problem with false positives. Incomplete CPE data, the machine-readable identifiers that specify affected products, increases the risk that teams spend cycles investigating vulnerabilities that do not apply to them, while potentially missing ones that do. Over time, that erodes confidence in the dataset and pushes organisations to build parallel intelligence pipelines, with the attendant cost and operational complexity that implies.
What the NVD Enrichment Backlog Means for Vulnerability Management
Moody argues that none of this reflects irresponsibility on NIST’s part. The scale problem is real and the existing model was not built for it. But the trade-off pushes more responsibility downstream, onto the organisations and tooling that consume NVD data. Vulnerability management is shifting from consuming a curated list to synthesising actionable intelligence from multiple incomplete sources in near real time.
That requires correlation across NVD, vendor advisories, independent vulnerability-intelligence providers, threat intelligence platforms, and internal asset inventories. Action1’s own approach, as Moody describes it, combines intelligence from VulnCheck NVD++, NIST NVD, CISA’s KEV Catalogue, Microsoft’s MSRC data, and vendor release notes, then scores each CVE against CVSS severity, KEV status, and known ransomware campaign usage to produce initial prioritisation in minutes. That assessment is then correlated with real-time endpoint data so that remediation can begin without a separate export or manual handoff.
The NVD will remain a component of that ecosystem, but NIST’s own announcement makes clear it will no longer function as a comprehensive baseline on its own. With only KEV-listed CVEs guaranteed enrichment within one business day, and the remaining volume left without a firm processing commitment, the gap between what the database reflects and what is actively being exploited in the field will remain a live problem for any team still treating NVD as their single source of truth.

