NVD's April policy did not remove the enrichment work. It moved it. This chart is how you find out how much of it moved to you.
The rule, published April 15: NVD enriches CVEs on CISA's KEV list, CVEs in software the federal government uses, and critical software under Executive Order 14028. Everything else is marked "not scheduled for immediate enrichment," which arrives in the API as Deferred and means no CPE. The CNA's own score usually still shows. The record does not look empty.
Of the 51,219 CVEs published in 2026 that NVD has settled, 20,076 are Deferred. That is 39%. The useful part is that it is predictable.
The rule is written about products. The result sorts by publisher. Patchstack, Wordfence and WPScan: 99% of their records Deferred. VulDB 70%, VulnCheck 52%, MITRE 47%, GitHub 27%. Microsoft, Chrome, Apple, Adobe and Mozilla: 0.0%. Take the three WordPress CNAs out and 12,608 Deferred CVEs remain. Severity does not change the answer: by the CNA's own score, Critical is Deferred at 46% and Low at 42%.
So find the CNAs that publish most of your CVEs and read your own number off the chart. If you live on WordPress plugins or open-source packages, most of your CPE matching is now yours to do, and that is a staffing question before it is a tooling one. Run a Microsoft and Chrome estate and almost nothing changed. The KEV half of the rule is holding either way: 140 of the 141 KEV-listed CVEs from 2026 are enriched and none is Deferred.
When NVD says Deferred, where does your CPE come from?
#vulnerabilitymanagement #cybersecurity #CVE #NVD
#nvd
2 posts · Last used 29d
The CVE program averted a funding emergency, but the crises of the last few years—like the NVD stopping work in 2024 and the 2025 funding scare—have eroded trust in the existing system.
The biggest takeaway from the chaos? Everyone should have a plan B.
Read Josh Bressers deep dive into the current state of vulnerability identifiers, the loss of trust, and what to expect next. https://anchore.com/blog/cve-is-saved-but-theres-work-to-do/
#Cybersecurity #VulnerabilityManagement #CVE #NVD
You've seen all posts