Desk live·
ForensicPost
Cloud/Vulnerabilities/File 26-0412

NIST Moves Vulnerability Database to Triage, Enriching 15-20% of CVEs

NIST moved the vulnerability database to a triage model in April 2026. An estimated 15–20% of incoming CVEs will receive full enrichment, prioritised by known exploitation and federal use.

Constructed geometry · not a chart of case data
TargetVulnerability management pipeline
ActorUnattributed
D. Kennedy11 min readConfidence: high3 sources reviewed

NIST transitioned the National Vulnerability Database to a triage model on 15 April 2026. Going forward an estimated 15% to 20% of incoming CVEs receive full enrichment, prioritised by membership of the known-exploited catalogue, federal government use, and critical-software designation.

Given the arithmetic in 26-0405 this is a defensible decision, and it changes what the database is.

The Prioritisation Is Sound And The Criteria Are Visible

Known-exploited vulnerabilities are the right first call: something being used against real targets outranks something theoretical. Federal use and critical-software status reflect the agency’s actual mandate.

Publishing the criteria is the important part. An organisation can now reason about what it will and will not receive, which is far better than an unexplained backlog.

But The Criteria Are Not Your Criteria

A vulnerability in software used by no federal agency, not yet observed in exploitation, in a product that is not designated critical, may never be enriched. If that product is central to your business, its absence from the enriched set says nothing about your risk.

Known-exploited status is also inherently retrospective. It is added after exploitation is observed, so the prioritisation cannot cover the window between disclosure and first observed use — which, per the research filed at 26-0630, has been compressing.

What Organisations Have To Do Now

The practical consequence is that a public good has become a partial service, and the remaining 80% is now a commercial market — vendors that maintain their own enrichment will sell it.

Larger organisations will buy that. Smaller ones will not, which reproduces the pattern this desk keeps filing: a shared resource degrades, capable organisations substitute, and the gap widens for everyone who cannot.

How we reported this

Compiled from published NIST announcements and vendor analysis, listed below. Enrichment percentages are as stated by the agency and its analysts. Corrections: corrections@forensicpost.com.

Sources
  1. NIST updates NVD operations to address record CVE growthNIST
  2. NVD changes 2026: NIST vulnerability database shiftBlack Duck
  3. NIST NVD update: what it means for your backlogTamnoon
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary