Commerce OIG pushes NIST to staff NVD backlog
The vulnerability database is still treated like shared infrastructure, which is exactly how critical systems become nobody’s staffing problem.
TL;DR
Federal News Network reports that a Commerce Office of Inspector General review found NIST’s National Vulnerability Database still needs more resources to work through a vulnerability-analysis backlog that began in 2024. The NVD gets about 300,000 hits a day and feeds defenders’ tools with enriched CVE data, including software-version mappings. NIST has already moved to a risk-based enrichment model, but the audit’s point is simpler: prioritization is not the same thing as capacity.
Federal News Network’s interview with Commerce OIG cybersecurity audit director Chuck Mitchell puts a practical problem under the polite label of “resource constraints.” NIST’s National Vulnerability Database is not just a website for searching bugs. It is a machine-readable dependency for vulnerability scanners, patch prioritization, asset-management workflows and the people who have to decide whether a specific software version is exposed. Mitchell said the NVD gets about 300,000 hits a day and pulls CVE data approximately hourly before NIST adds the details defenders actually use.
The backlog story is not new, which is the problem. NIST acknowledged in 2024 that the NVD had a growing backlog and said it had reassigned staff while seeking agency-partner support and longer-term fixes, including a possible consortium: https://nvd.nist.gov/general/news/nvd-program-transition-announcement. In April 2026, NIST said CVE submissions had increased 263% from 2020 to 2025, that first-quarter 2026 submissions were nearly one-third higher than the same period a year earlier, and that the program enriched nearly 42,000 CVEs in 2025, 45% more than any prior year: https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth.
NIST’s operational answer is triage. Since April 15, 2026, it has prioritized enrichment for CVEs appearing in CISA’s Known Exploited Vulnerabilities catalog, with a goal of enrichment within one business day, while other CVEs can be listed as “Lowest Priority - not scheduled for immediate enrichment”: https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth. That is defensible emergency medicine. It is not a cure.
For practitioners, the Monday problem is dependency management. If your vulnerability process assumes every NVD record will promptly carry full enrichment, product matching and prioritization data, that assumption is no longer safe. The OIG audit lands on the unglamorous fix: staff and sustain the infrastructure instead of admiring how many downstream systems quietly depend on it.
Published ·Deep Fathom