NIST's NVD Faces Backlog Crisis Amid Management Failures

NIST's NVD Faces Backlog Crisis Amid Management Failures

First seen 1 Jun 2026, 12:50 UTC CyberscoopFeeds2.FeedburnerTherecord.MediaHeise.DeTechtimes+12 87% similarity 36.9

Article Content

Browse articles
ThreatCluster

The National Institute of Standards and Technology (NIST) has halted evaluations of IT security vulnerabilities using the Common Vulnerability Scoring System (CVSS) due to a growing backlog in the National Vulnerability Database (NVD). The backlog grew from 13,000 unprocessed vulnerabilities in June 2024 to over 27,000 by the end of 2025. A recent inspector general report highlighted poor planning, inefficient operations, and duplication of efforts between NIST and the Cybersecurity and Infrastructure Security Agency (CISA). NIST's inability to clear the backlog has undermined the utility and public trust in the NVD, which is crucial for cybersecurity professionals. The report also criticized NIST for a lack of strategic planning and communication failures that exacerbated the situation. As of April 2026, the NVD sees over 300,000 daily users, indicating its importance in the cybersecurity landscape. The Inspector General's office has proposed reducing unnecessary tasks to redirect resources towards clearing the backlog.

Key Points: • NIST has stopped evaluating vulnerabilities using CVSS due to a backlog crisis. • The backlog in the NVD grew from 13,000 to over 27,000 unprocessed vulnerabilities from 2024 to 2025. • An inspector general report cited poor planning and duplication of efforts as core issues.

ThreatCluster AI

Timeline

2024-02-01
NVD backlog begins
The backlog of unprocessed vulnerabilities started to grow after the enrichment contract lapsed.
Cyberscoop
2024-06-01
Backlog reaches 13,000
The number of unprocessed vulnerabilities in the NVD reached 13,000 as reported in June 2024.
Cyberscoop
2025-12-31
Backlog exceeds 27,000
By the end of 2025, the backlog of unprocessed vulnerabilities exceeded 27,000, raising concerns about NVD's effectiveness.
Therecord.Media
2026-04-01
NVD sees 300,000 daily users
The NVD reported an average of over 300,000 unique users per day, highlighting its critical role in cybersecurity.
Heise.De
2026-05-29
Inspector General report released
A report from the Department of Commerce's Inspector General outlined NIST's mismanagement of the NVD.
Cyberscoop

Community

Browse all →