Feeds2.Feedburner NIST's NVD Faces Backlog Crisis Amid Management Failures
Article Content
- •NIST has stopped evaluating vulnerabilities using CVSS due to a backlog crisis.
- •The backlog in the NVD grew from 13,000 to over 27,000 unprocessed vulnerabilities from 2024 to 2025.
- •An inspector general report cited poor planning and duplication of efforts as core issues.
The National Institute of Standards and Technology (NIST) has halted evaluations of IT security vulnerabilities using the Common Vulnerability Scoring System (CVSS) due to a growing backlog in the National Vulnerability Database (NVD). The backlog grew from 13,000 unprocessed vulnerabilities in June 2024 to over 27,000 by the end of 2025. A recent inspector general report highlighted poor planning, inefficient operations, and duplication of efforts between NIST and the Cybersecurity and Infrastructure Security Agency (CISA). NIST's inability to clear the backlog has undermined the utility and public trust in the NVD, which is crucial for cybersecurity professionals. The report also criticized NIST for a lack of strategic planning and communication failures that exacerbated the situation. As of April 2026, the NVD sees over 300,000 daily users, indicating its importance in the cybersecurity landscape. The Inspector General's office has proposed reducing unnecessary tasks to redirect resources towards clearing the backlog.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (22)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…