A Department of Commerce Office of Inspector General audit published in May 2026 found that the National Vulnerability Database backlog had grown beyond 27,000 unprocessed vulnerabilities, that NIST lacked a strategic plan for managing it, and that annual disclosures were projected to exceed 60,000 in 2026.
This is the least visible dependency in commercial security, and almost every organisation relies on it without knowing.
What Enrichment Actually Provides
A CVE identifier by itself is a name. What makes it actionable is the analysis attached afterwards: a severity score, the affected product and version ranges expressed in a machine-readable form, and the weakness classification.
That metadata is what vulnerability scanners match against, what patch prioritisation queries sort by, and what compliance regimes reference when they require critical vulnerabilities to be remediated within a stated window.
Without it, a vulnerability exists, is public, may be exploited — and is invisible to the tooling an organisation uses to find out.
The Obligations Are Written Against The Metadata
Contractual and regulatory language routinely says something like "remediate critical vulnerabilities within 15 days". Critical, in practice, means a severity score in this database.
An unenriched vulnerability has no score, and therefore no obligation attaches to it. An organisation can be fully compliant while unpatched against something being actively exploited — not through negligence, but because the process it was told to follow has a gap in its input.
Volume Is The Cause, Not Funding Alone
Sixty thousand disclosures a year is not a staffing problem that a modest budget increase resolves. It reflects more software, more researchers, more automated discovery, and a supply chain that generates a CVE for every affected package rather than one for the underlying defect.
A centralised human-analysis model was viable at a few thousand a year. It is arithmetic that it is not viable at sixty thousand, and the audit finding of no strategic plan is the more serious half of the report.
Compiled from published audit findings and analysis, listed below. Backlog and projection figures are as reported. Corrections: corrections@forensicpost.com.