TL;DR: NIST’s update to the National Vulnerability Database will leave more CVEs partially enriched or delayed, forcing vulnerability teams to prioritise with incomplete product mappings, severities, and references according to Nucleus. The shift makes decision latency, not raw visibility, the dominant operational risk.
NHIMG editorial — based on content published by Nucleus: NIST’s NVD update and the future of vulnerability prioritisation
By the numbers:
- 2026 will likely be the first year ever to exceed 50,000 published CVEs.
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: What breaks when vulnerability enrichment becomes delayed or selective?
A: Prioritisation breaks first.
Q: When should organisations stop relying on CVSS as the primary prioritisation signal?
A: They should stop when CVSS is the only stable signal left.
Q: What do security teams get wrong about vulnerability management in complex environments?
A: They often treat the software flaw as the whole problem.
Practitioner guidance
- Implement enrichment-independent triage rules Route vulnerabilities using exploit evidence, asset criticality, and known exposure paths so that missing CVSS or CPE data does not halt prioritisation.
- Re-baseline remediation SLAs around decision latency Track the time it takes to move from CVE arrival to an assigned action, especially when scanner output must be reconciled with incomplete metadata.
- Correlate vulnerability queues with identity exposure Check whether affected systems are reachable through service accounts, API keys, or third-party access paths, then prioritise accordingly.
What's in the full article
Nucleus's full article covers the operational detail this post intentionally leaves for the source:
- How its threat rating normalises exploit pressure when NVD enrichment is missing or delayed
- Examples of how teams can route vulnerabilities into remediation workflows without waiting for complete CVSS or CPE data
- The platform logic for combining public enrichment, exploit evidence, and asset context into one decision path
- How the vendor frames automation and reporting when enrichment fields are incomplete
👉 Read Nucleus's analysis of how NVD enrichment delays affect vulnerability prioritisation →
NVD enrichment delays: what vulnerability teams need to change now?
Explore further
Decision latency is the new failure mode in vulnerability management. The article shows that most teams will still see the CVE, but they will lose the enriched context that turns a finding into a decision. That is a governance problem because remediation SLAs, escalation rules, and accountability all depend on consistent metadata. The practical conclusion is that vulnerability programmes must now be designed to act under incomplete information.
A question worth separating out:
Q: Who is accountable when delayed enrichment causes a missed remediation window?
A: Accountability sits with the programme owner, not the metadata source. Teams must define who owns triage, who resolves conflicts, and who can override automation when enrichment is missing. Governance frameworks should treat delayed context as an operational risk that requires explicit decision ownership.
👉 Read our full editorial: NVD enrichment delays expose the limits of CVE-led prioritisation