Feeds2.Feedburner
NIST's NVD Faces Backlog Crisis Amid Management Failures
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The National Institute of Standards and Technology (NIST) has halted evaluations of IT security vulnerabilities using the Common Vulnerability Scoring System (CVSS) due to a growing backlog in the National Vulnerability Database (NVD). The backlog grew from 13,000 unprocessed vulnerabilities in June 2024 to over 27,000 by the end of 2025. A recent inspector general report highlighted poor planning, inefficient operations, and duplication of efforts between NIST and the Cybersecurity and Infrastructure Security Agency (CISA). NIST's inability to clear the backlog has undermined the utility and public trust in the NVD, which is crucial for cybersecurity professionals. The report also criticized NIST for a lack of strategic planning and communication failures that exacerbated the situation. As of April 2026, the NVD sees over 300,000 daily users, indicating its importance in the cybersecurity landscape. The Inspector General's office has proposed reducing unnecessary tasks to redirect resources towards clearing the backlog.
Key Points: • NIST has stopped evaluating vulnerabilities using CVSS due to a backlog crisis. • The backlog in the NVD grew from 13,000 to over 27,000 unprocessed vulnerabilities from 2024 to 2025. • An inspector general report cited poor planning and duplication of efforts as core issues.