What just happened?
After a funding lapse in 2024, the National Institute of Standards and Technology (NIST) decided to trim the scope of its National Vulnerability Database (NVD). Instead of cataloguing every single CVE, NIST will now prioritize only those that are already on the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog.
In plain English – NIST is saying, “We’ll only publish the bugs that attackers are actually using in the wild.” The goal? Clear a backlog that grew to over 30,000 unprocessed entries and get the NVD back to a usable, up‑to‑date state.
Why the backlog mattered
The NVD is the go‑to reference for every security product, from firewalls to cloud scanners. When the database lags, vendors ship updates based on stale data, and organisations end up patching the wrong things. The 2024 funding gap meant NIST staff were short‑handed, and new CVE submissions piled up faster than they could be vetted.
How the new priority works
CISA maintains a KEV list that currently holds about 250 high‑risk CVEs – the ones that have been seen in real attacks, are weaponised, or have active exploit kits. NIST will now:
- Immediately publish any new CVE that appears on CISA’s KEV list.
- Continue to accept all CVE submissions, but only fast‑track those that match KEV criteria.
- Defer or delay publishing low‑risk, un‑exploited CVEs until resources allow.
Numbers you need to know
- Backlog before the change: ~31,000 pending CVEs.
- CISA KEV catalog size (as of April 2026): ~260 entries.
- Projected reduction in NVD publication lag: from >90 days to <30 days for KEV CVEs.
Impact on Indian enterprises
Most Indian IT services, banks, and e‑commerce platforms rely on NVD feeds for vulnerability management. Here’s why the shift matters locally:
- Faster patch cycles. If a CVE lands in CISA’s KEV list, you’ll see it in NVD within a day, giving you a tighter window to apply patches before attackers strike.
- Prioritisation clarity. Security teams can now focus on the 2‑3 % of CVEs that actually see real‑world exploitation, saving time and reducing alert fatigue.
- Potential blind spots. Low‑risk vulnerabilities might be delayed. If your stack includes niche software not on the KEV list, you’ll need supplemental feeds (e.g., vendor advisories, GitHub Security Advisories).
What Indian security teams should do now
- Integrate CISA KEV feeds. Add https://www.cisa.gov/known-exploited-vulnerabilities-catalog.csv to your SIEM or vulnerability scanner.
- Keep secondary sources. Subscribe to vendor‑specific bulletins (Microsoft Security Update Guide, Red Hat CVE Tracker, etc.) for non‑KEV bugs.
- Re‑evaluate patch windows. For KEV CVEs, aim for a 48‑hour remediation window; for others, follow your existing risk‑based schedule.
- Educate stakeholders. Explain that a slower NVD for non‑KEV bugs isn’t a sign of negligence – it’s a resource re‑allocation.
TamilTech’s take
We think the move is pragmatic. The NVD was becoming a data swamp, and Indian organisations have been drowning in alerts for years. By laser‑focusing on the “real‑world” threats, NIST is giving security teams a clearer signal.
That said, the Indian market runs a lot of legacy ERP and telecom gear that rarely appears on the KEV list. Companies should not drop their existing vulnerability‑management processes; instead, treat the KEV‑only NVD as a high‑priority supplement.
What’s next?
Watch for two things:
- Funding restoration. If Congress restores NIST’s budget, we may see the backlog gradually cleared and the scope broadened again.
- Expanded KEV criteria. CISA is already planning to add “high‑impact” vulnerabilities that haven’t yet been weaponised but have high exploit potential. That could broaden the NVD’s fast‑track list.
For now, Indian security teams should double‑down on KEV feeds, keep an eye on vendor advisories, and use the lull in low‑risk CVE noise to finally get ahead of the real threats.




Comments (0)
Be the first to comment!