Reconsidering the NVD Triage Decision
Three design choices within NIST's 15 April 2026 decision are independently fixable at roughly the same cost and the window in which those refinements can credibly be made is about ninety days.
NTSC THE FUTURE OF CVE JUNE 2, 2026
On 15 April 2026, the National Institute of Standards and Technology (NIST) announced that the U.S. National Vulnerability Database (NVD) will no longer provide full enrichment for most Common Vulnerabilities and Exposures (CVEs) submitted to it. This paper sets out a position on how that decision should be challenged. The position is not that the announcement should be reversed in full. Rather, it is that three specific design choices within the announcement are independently fixable at roughly the same cost to NIST, that fixing them would materially reduce the risk created for organizations that depend on NVD enrichment, and that the window in which those refinements can credibly be made is approximately ninety days.
NIST stated that it will focus NVD enrichment efforts on three priority groups of vulnerabilities: CVEs listed in CISA's Known Exploited Vulnerabilities (KEV) catalog; CVEs affecting software used across the United States federal government; and CVEs associated with "critical software" as defined in Executive Order 14028, a U.S. federal procurement definition published in 2021.
All other CVEs will continue to be listed in the NVD, but marked Not Scheduled - no enrichment work is planned. CVEs published before 1 March 2026 that were still awaiting enrichment have been moved into the same Not Scheduled state, to be revisited only if resources permit.
Two additional changes warrant explicit attention. First, NIST will no longer routinely provide its own independent severity score (CVSS) when a score has already been supplied by the organization that disclosed the vulnerability - in practice shifting responsibility for severity assessment to the disclosing party. Second, product identification data used by security tools to match vulnerabilities to deployed software (Common Platform Enumeration, or CPE) has been cut back alongside CVSS analysis, even though generating product identifiers is substantially more amenable to automation than severity analysis.
A subsequent NIST announcement on 28 May 2026 partially addresses the product-identification question, and it is important to characterize it precisely. Effective 17 June 2026, the NVD will include the "affected" product information already present in a CVE record - the field within the CVE Record Format that can carry product identifiers - in its data feed and API, alongside Stakeholder-Specific Vulnerability Categorization (SSVC) data from CISA. This is a welcome and constructive step. It is, however, a decision to surface what a submitter has already provided, not to generate or guarantee that information. The NVD will pass through whatever product identification a submitter included; it does not commit NVD to producing an identifier where the submitter supplied none, and submitter population of these fields remains optional under the CVE Record Format. The distinction between surfacing existing data and ensuring usable data exists for every CVE is the precise gap the first of the three asks below addresses.
The timing of the NVD decision materially increases its impact. Multiple frontier artificial-intelligence models have recently demonstrated the ability to discover, analyze, and operationalize software vulnerabilities with minimal human involvement, dramatically compressing the time between public disclosure of a vulnerability identifier and the creation of a working exploit. Tasks that previously required highly skilled researchers days or weeks can now be performed autonomously in hours, at very low marginal cost.
This shift affects defenders and attackers differently. Defenders gain new capabilities to identify weaknesses earlier - but only if existing disclosure, patching, and enrichment pipelines can absorb that information quickly. Attackers, by contrast, can take immediate advantage of newly disclosed vulnerabilities without needing organizational change or additional process. NVD enrichment sits directly in this gap: it is one of the primary mechanisms defenders use to triage, prioritize, and act within a shrinking window. Reducing that enrichment at the same moment exploitation is accelerating does not eliminate analyst work; it shifts effort and advantage toward attackers who no longer need it.
The announcement in its current form directly amplifies several categories of risk - the considerations that should drive a request for refinement.
This position does not ask NIST to expand its workload or revisit its capacity constraints. It accepts the tiered approach as the working framework and does not argue for a return to historical levels of enrichment. Instead, it identifies three narrow refinements that are defensible on engineering, cost, and governance grounds consistent with existing security, compliance, and risk-management objectives, and committing no one to a broader policy stance.
Each request addresses a specific harm created by the current policy design.
Over the next ninety days, security-tool vendors, regulators, and audit bodies will adapt their guidance and workflows to the new NVD operating model. After that point, changes become disruptive rather than corrective, and the cost - political and operational - of revisiting the policy rises sharply. The same period is when advanced Al models for vulnerability discovery and exploitation are likely to see broader real-world use. The window in which refinement is both most feasible and most necessary is therefore the same window.
NIST may be correct in its assessment of resource constraints. The design of the cut is the element that can still be improved. Automated vulnerability discovery and exploitation do not slow to match enrichment capacity, and the publication of a CVE identifier now marks the beginning of the race between defenders and attackers. Three focused, cost-neutral refinements - preserving product identification, prioritizing enrichment by exploitation risk, and retaining independent severity scoring where it matters most restore a critical defensive layer without reopening the broader capacity debate. This is the decision NIST should be asked to make while the opportunity still exists.