Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NIST Adjusts CVE Handling Amid Rising Submissions

NIST Adjusts CVE Handling Amid Rising Submissions

Posted on April 17, 2026 By CWS

The National Institute of Standards and Technology (NIST) has revised its approach to handling cybersecurity vulnerabilities listed in its National Vulnerability Database (NVD). This change comes in response to a significant increase in vulnerability submissions, which have surged by 263% from 2020 to 2025. Under the new guidelines, only vulnerabilities that meet specific criteria will be enriched by NIST.

New Criteria for CVE Enrichment

As of April 15, 2026, NIST has established a set of criteria for prioritizing CVE enrichment. Vulnerabilities included in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, those used within the federal government, and critical software vulnerabilities as defined by Executive Order 14028 are prioritized. The goal of these criteria is to focus enrichment efforts on vulnerabilities with the greatest potential for widespread impact.

Vulnerabilities that do not meet these criteria will be categorized as “Not Scheduled” for enrichment, although they will still be listed in the NVD. This decision reflects a need to manage resources effectively amidst a growing volume of vulnerabilities requiring attention.

Implications for Security Research

NIST’s announcement highlights the challenges posed by the increasing volume of vulnerabilities. In the first quarter of 2026 alone, submissions were nearly a third higher than the same period last year. Despite these challenges, NIST managed to enrich approximately 42,000 CVEs in 2025, marking a 45% increase compared to previous years.

Security researchers and organizations relying on NIST as a primary source for CVE data may need to adjust their strategies. While high-impact CVEs that are initially unscheduled can be requested for enrichment via email, the new approach prioritizes vulnerabilities that pose systemic risks over those with isolated impacts.

Future Outlook in Cybersecurity Management

The changes instituted by NIST reflect a broader shift towards a risk-based approach in vulnerability management. Caitlin Condon from VulnCheck emphasized the need for distributed and machine-speed solutions to address today’s complex threat landscape. Additionally, David Lindner of Contrast Security noted that organizations must now focus more on actionable intelligence rather than sheer volume of data.

As the cybersecurity field evolves, entities must adapt to a proactive risk management strategy. By concentrating on the most critical vulnerabilities and leveraging threat intelligence, the industry can enhance its resilience against cyber threats. This approach not only aligns with current technological advancements but also addresses the interconnected nature of global cybersecurity challenges.

The Hacker News Tags:CISA, CVE, CVE enrichment, Cybersecurity, NIST, risk management, security research, threat intelligence, vulnerability database, vulnerability management

Post navigation

Previous Post: Windows 11 Updates May Trigger BitLocker Recovery
Next Post: Cursor AI Flaw Endangers Developer Systems

Related Posts

Critical Metro4Shell Vulnerability Exploited in React Native Critical Metro4Shell Vulnerability Exploited in React Native The Hacker News
UNC6692 Uses Teams to Spread SNOW Malware UNC6692 Uses Teams to Spread SNOW Malware The Hacker News
5 Threats That Reshaped Web Security This Year [2025] 5 Threats That Reshaped Web Security This Year [2025] The Hacker News
Malicious VS Code Extensions Target Crypto Wallets Malicious VS Code Extensions Target Crypto Wallets The Hacker News
CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures The Hacker News
131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign 131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Launch Password-Spraying Assault on AWS Accounts
  • BGP Hijack Targets Softaculous, Delivers Malicious Update
  • PaperCut Vulnerabilities Lead to Active Cyber Intrusions
  • Anthropic Enhances Claude Security Following AI Breaches
  • Brave’s Email Aliases Enhance Privacy in Browser Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Launch Password-Spraying Assault on AWS Accounts
  • BGP Hijack Targets Softaculous, Delivers Malicious Update
  • PaperCut Vulnerabilities Lead to Active Cyber Intrusions
  • Anthropic Enhances Claude Security Following AI Breaches
  • Brave’s Email Aliases Enhance Privacy in Browser Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark