Listen to this Post
The US National Vulnerability Database (NVD) is in the midst of a major transformation. After a challenging year of internal restructuring and a growing mountain of unprocessed vulnerabilities, the organization is now trying to regain its footing. Despite recent progress in rebuilding its team and enhancing its capabilities, the NVD is now facing another hurdle: a dramatic spike in reported vulnerabilities that threatens to overwhelm its operations once again.
At the VulnCon conference on April 10 in Raleigh, North Carolina, key NVD figures—Program Manager Tanya Brewer and Computer Security Division Chief Matthew Scholl—disclosed a comprehensive update on the database’s state. From efforts to automate data enrichment and explore AI-driven solutions to abandoning plans for a public-private consortium, the NVD is clearly in a period of flux.
Below is a deep dive into the situation and what it means for cybersecurity professionals, software vendors, and the global vulnerability management community.
Rebuilding and Recovery:
- The NVD suffered a major disruption in early 2024 when its supporting contract ended, triggering staff departures and major slowdowns in processing.
- CVE (Common Vulnerabilities and Exposures) enrichment almost halted between March and May 2024, dropping below 2,000 processed monthly.
- A new commercial contract was signed in June 2024, bringing in fresh personnel and gradually restoring processing capacity.
- By 2025, processing returned to pre-disruption levels, reaching around 3,000 CVEs monthly.
- Brewer confirmed the new team is fully trained and operational, composed of analysts, developers, and specialists in standards and governance.
- Despite concerns about broader government budget cuts, Scholl assured the audience that NVD remains a NIST priority and will receive proper funding.
The Backlog Crisis Persists Despite Progress
- Despite ramped-up efforts, the vulnerability backlog ballooned from 17,000 in August 2024 to 25,000 by March 2025.
- A staggering 32% rise in CVE submissions during 2024, compounded by a 48% year-over-year growth in early 2025, is overwhelming current processing capacities.
- NVD admitted its current rate of CVE analysis is insufficient to keep up with the influx.
Strategic Shifts: Old CVEs Deferred, New Gaps Filled
- To save resources, all pre-2018 CVEs pending enrichment are now marked as “Deferred” and will no longer be prioritized unless new, urgent data emerges.
- Post-2018 CVEs will be enriched using data from CVE Numbering Authorities (CNAs) rather than being built from scratch.
- This “gap-filling” method is seen as a temporary measure, though it might become permanent depending on long-term effectiveness.
Automation and AI on the Horizon
- NVD is developing an automation tool to generate Common Platform Enumeration (CPE) data using machine learning.
- Efforts are underway to automate Linux kernel CVE processing by using AI to identify vulnerabilities, assign CVSS scores, and tag common weaknesses.
- An overhauled internal vulnerability console, upgraded API, improved NVD search engine, and a refreshed data ontology (Vulntology) are also part of ongoing improvements.
Transparency and Community Engagement: Room for Improvement
- Industry experts expressed frustration with the lack of public communication from the NVD, particularly during the brief 30-minute VulnCon session.
- Critics such as Brian Martin and Jeroen Braak felt key questions went unanswered.
– Scholl defended the
Calls for Decentralization and Data Source Diversification
- As delays persist, thought leaders urge cybersecurity teams to diversify their CVE data sources.
- Platforms such as CVE.org, vendor advisories, CISA KEV, OSV.dev, and ExploitDB are gaining traction as alternative data feeds.
- Scholl agreed that a wider ecosystem of data providers could ultimately strengthen the cybersecurity community’s resilience.
What Undercode Say:
The resurgence of the NVD highlights both the strengths and weaknesses of centralized vulnerability databases in today’s fast-evolving digital threat landscape.
From a structural standpoint, the NVD’s dependency on external contracts illustrates a fragility that can severely impact national cybersecurity posture. The temporary collapse in CVE processing between March and June 2024 showed how a bureaucratic hiccup can ripple across global vulnerability intelligence systems.
However, the team’s ability to bounce back by late 2024—processing nearly 3,000 CVEs monthly in 2025—is a testament to institutional resilience and rapid onboarding. It demonstrates the importance of having contingency plans, cross-trained teams, and automation-ready pipelines.
Yet, this recovery is being challenged by an even larger problem: the volume of new vulnerabilities. The explosive growth of 32% in 2024 and 48% by March 2025 isn’t just a technical issue; it reflects a growing attack surface, expanding software ecosystems, and increased transparency in vulnerability disclosure.
The shift in strategy from full enrichment to “gap filling” is both practical and concerning. While it allows for faster processing, it risks reducing the quality and depth of vulnerability metadata. This could have downstream consequences for organizations that rely on detailed data for risk prioritization and patch management.
Deferring pre-2018 CVEs is a logical choice given the resource constraints. However, it raises philosophical questions about long-term vulnerability stewardship. Should historical CVEs be preserved with the same diligence as newer ones? Or is triage simply inevitable in the face of an unmanageable surge?
The
Transparency remains an
Finally, the growing momentum behind decentralized data sources is healthy. Encouraging organizations to look beyond the NVD fosters innovation, reduces single points of failure, and democratizes threat intelligence. The security community is best served by a collaborative, multifaceted ecosystem where no one source is solely relied upon.
In sum, the NVD’s current chapter is one of rebuilding under pressure. Its trajectory will depend on how well it balances speed, accuracy, transparency, and innovation
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
Undercode AI
Image Source:
Pexels
Undercode AI DI v2





