CVE processing shift: New rules target rising submissions

NIST will prioritize KEV, federal software and EO 14028 critical software, while lower-priority CVEs remain listed.

NIST is revising its process for handling cybersecurity vulnerabilities and exposures, or CVEs, listed in the NIST National Vulnerability Database (NVD). Previously, the NVD program analyzed all CVEs to add details such as severity scores and product information to support vulnerability assessment and remediation.

For Control Engineering subscribers, cybersecurity risk prioritization is important because it provides another metric to consider during a cybersecurity risk assessment.

Under the revised process, NIST will enrich CVEs that meet defined criteria. CVEs that do not meet those criteria will still be listed in the NVD, but they will be assigned lower priority for enrichment and may not be enriched immediately.

This change is driven by an increase in CVE submissions, which rose 263% between 2020 and 2025. NIST expects this trend to continue. Submissions during the first three months of 2026 were approximately 33% higher than during the same period last year.

Processing volume has increased compared with previous years. In 2025, nearly 42,000 CVEs were enriched, 45% more than in any prior year. However, that higher output is insufficient to match the growth in submissions. As a result, NIST is implementing a revised process. The changes described below are intended to prioritize selected CVEs, provide clarity on current workload management, and support more consistent operations while automated systems and workflow improvements are developed for long-term scalability.

New prioritization criteria

Starting on April 15, 2026, NIST will prioritize the following CVEs for enrichment:

All submitted CVEs will still be added to the NVD. However, those that do not meet the criteria above will be categorized as “Lowest Priority – not scheduled for immediate enrichment.” This approach is intended to prioritize CVEs with the highest potential impact across multiple systems. While CVEs outside these criteria may still significantly affect individual systems, they generally do not present the same level of broader operational risk as those in the prioritized categories.

These criteria may not identify every potentially high-impact CVE. Request for enrichment of any CVE categorized as lowest priority may be submitted by emailing [email protected]. Those requests will be reviewed and the CVEs will be scheduled for enrichment based on available resources.

The definition of critical software and a description of the new workflow, including how  the processing queue will be prioritized, are available on the NVD website.

Streamlining severity scores

Previously, NIST has provided its own severity score for all submitted CVEs, including those for which the CVE Numbering Authority had already supplied a severity score. Under the revised process, a separate NIST severity score will no longer be automatically provided for those CVEs. This change will reduce duplicate scoring and allow resources to be allocated to higher-priority tasks.

Handling of modified CVEs

NIST is revising its process for reanalyzing enriched CVEs that are modified after enrichment. Under the previous policy, all modified CVEs were reanalyzed. Under the revised process, reanalysis will occur only when NIST becomes aware of a modification that significantly affects the enrichment data. Users may request reanalysis of specific modified CVEs by emailing NIST at the address listed above.

Because of this process change, all CVEs marked as deferred last year, as described in the April 2, 2025 NVD General Announcement, will be moved to “Modified After Enrichment.” Because of the volume of CVEs involved, these CVEs will be recategorized in batches during the next two weeks.

The CVE backlog

Starting in early 2024, the NVD accumulated a backlog of unenriched CVEs. That backlog has not been cleared, partly because submission volume has increased. When the new prioritization criteria described above are implemented, all backlogged CVEs with an NVD publish date earlier than March 1, 2026, will be moved to the “Not Scheduled” category. Those earlier vulnerabilities may be considered for enrichment under the new prioritization criteria based on available resources. The backlog does not include any CVEs in the KEV Catalog, as those have consistently been prioritized for enrichment under the existing risk-based prioritization approach.

New status labels and other information

To clarify CVE status, NIST is updating CVE status labels and descriptions. Additional information is available on the CVE statuses page, and further details on the revised process are available on the CVEs and the NVD Process page. In addition, the NVD Dashboard has been updated to report the status of all CVEs and other NVD statistics with current data.

These changes will affect users. However, this risk-based approach is necessary to manage the current increase in CVE submissions while NVD operations are aligned with user and stakeholder needs. This change also allows resources to be directed to the development of automated systems and workflow improvements needed to support the program’s long-term operation.

NIST will continue to maintain the NVD as an important part of the nation’s cybersecurity infrastructure. By updating the NVD in response to current demands, the database can remain a reliable and publicly available source of information on cybersecurity vulnerabilities.

Edited by Puja Mitra, WTWH Media, for Control Engineering, from a NIST news release.

You also might like

https://www.controleng.com/industrial-cyber-security