NIST transitioned the National Vulnerability Database to a triage model on 15 April 2026. Going forward an estimated 15% to 20% of incoming CVEs receive full enrichment, prioritised by membership of the known-exploited catalogue, federal government use, and critical-software designation.
Given the arithmetic in 26-0405 this is a defensible decision, and it changes what the database is.
The Prioritisation Is Sound And The Criteria Are Visible
Known-exploited vulnerabilities are the right first call: something being used against real targets outranks something theoretical. Federal use and critical-software status reflect the agency’s actual mandate.
Publishing the criteria is the important part. An organisation can now reason about what it will and will not receive, which is far better than an unexplained backlog.
But The Criteria Are Not Your Criteria
A vulnerability in software used by no federal agency, not yet observed in exploitation, in a product that is not designated critical, may never be enriched. If that product is central to your business, its absence from the enriched set says nothing about your risk.
Known-exploited status is also inherently retrospective. It is added after exploitation is observed, so the prioritisation cannot cover the window between disclosure and first observed use — which, per the research filed at 26-0630, has been compressing.
What Organisations Have To Do Now
The practical consequence is that a public good has become a partial service, and the remaining 80% is now a commercial market — vendors that maintain their own enrichment will sell it.
Larger organisations will buy that. Smaller ones will not, which reproduces the pattern this desk keeps filing: a shared resource degrades, capable organisations substitute, and the gap widens for everyone who cannot.
Compiled from published NIST announcements and vendor analysis, listed below. Enrichment percentages are as stated by the agency and its analysts. Corrections: corrections@forensicpost.com.