Nottingham University data breach_cybersecurity for education industry
Nottingham University data breach_cybersecurity for education industry

NIST CVE Enrichment Rises by 45%: A CISO’s Guide to Smarter Vulnerability Intelligence

NIST CVE Enrichment Rises by 45%: A CISO’s Guide to Smarter Vulnerability Intelligence

CVE volume is on the rise. Learn how vulnerability intelligence helps CISOs prioritize exploitable, exposed vulnerabilities using business context and attack path mapping.

Read Time

7 min read

Posted On

Social Media

The challenge in the vulnerability intelligence process has shifted from finding vulnerabilities to prioritizing the right ones before attackers exploit them. In 2025, NIST enriched nearly 42,000 Common Vulnerabilities and Exposures (CVEs), which is a 45% increase over any previous year. Yet even this record output could not keep pace with submissions. CVE submissions increased 263% between 2020 and 2025, while submissions in the first quarter of 2026 were nearly one-third higher than during the same period in 2025.

This massive increase in the number of enriched CVEs in NIST's National Vulnerability Database (NVD) makes the vulnerability management process more challenging for enterprise security teams. The higher number of CVEs means increased critical and exploitable exposures for security teams to prioritize, which can overwhelm even a well-resourced security team very fast without any positive result to show.  

Key Takeaways: 

  • Rising CVE volumes make severity-only prioritization unsustainable.

  • Prioritize vulnerabilities using exploitability, internet exposure, business impact, and attack path context.

  • Agentic AI correlates these signals to help security teams remediate the most consequential vulnerabilities faster.

The NIST CVE Enrichment Volume Is Growing Faster Than Traditional Triage Can Scale

In its latest update published in April 2026, NIST has announced that they are bringing changes to its NVD operations. They are now adopting a risk-based enrichment model to adjust to the growing volume of vulnerability submissions, which demonstrates the scale of the problem. Rather than immediately enriching every published CVE, NIST will prioritize vulnerabilities that:

  • Appear in CISA’s Known Exploited Vulnerabilities catalog

  • Affect software used by the US federal government

  • Affect critical software as defined under Executive Order 14028

Other submitted CVEs will remain available in the National Vulnerability Database but may be categorized as lowest priority and not scheduled for immediate enrichment. NIST has also moved older backlogged vulnerabilities into a “Not Scheduled” category while it develops more sustainable automated workflows.

The new enrichment model is adopted to prioritize the critical vulnerabilities. However, it does not imply that other listed vulnerabilities are not important. This update brings a significant change to how CISOs view CVEs and how they prioritize vulnerability patches. With increased CVE volume, enterprise security programs face the same constraint. Teams cannot patch everything simultaneously, and treating every critical CVSS score as an emergency often creates more activity without effective reduction of breach risk. Thus, CISOs need to shift their focus to impact-based vulnerability prioritization for faster detection and response. 

Why CVSS-First Prioritization Creates a False Sense of Urgency

CVSS scores are valuable for measuring the technical severity of a vulnerability, but do not show how it affects the organization's systems or its impact on security, operations, or business continuity. A critical vulnerability on an isolated test server might pose significantly less risk than a mid-severity flaw on an exposed identity system.

This is why CISOs must learn to prioritize CVEs using attack path context, exploitability, exposure, and business impact. This will effectively reduce the number of vulnerabilities to work with, while improving the team’s chances of patching the critical ones before exploitation begins.

Vulnerability Exploitation Is Becoming a Primary Entry Point

The need for contextual prioritization is reinforced by the 2026 Verizon Data Breach Investigations Report. According to their latest release, exploitation of software vulnerabilities accounted for 31% of known initial access vectors, making it the most common entry point in the dataset. 

The challenge of effective vulnerability patching is further highlighted by the report, which also highlights a steep remediation gap. Only 26% of critical vulnerabilities listed in the CISA KEV catalog were fully remediated during 2025. Median time to full resolution increased to 43 days, which was almost two weeks longer than in 2024.

This disparity between the rising CVE volume and declining patching rates presents a concerning picture for the CISOs and enterprise security teams and their security teams. Attackers are increasingly using vulnerabilities for initial access, while organizations are taking longer to resolve vulnerabilities already known to be exploited. It is clear that only adding more findings to a dashboard will not close this gap. Security teams need a prioritization model based on exploitability, exposure, and business impact.

How to Manage Vulnerability Volume Rise with Efficient Prioritization?

In order to prioritize vulnerabilities, CISOs need contextual information that can help them separate noise from relevant intelligence. In this section, we will be highlighting the three primary context layers that help CISOs prioritize vulnerabilities for more effective and time-efficient patch management.

1. Exploitability: Can attackers use the vulnerability now?

In a threat and vulnerability management workflow, exploitability analysis needs to move beyond theoretical severity. It should consider whether a CVE appears in the CISA KEV catalog, whether exploit code or proof-of-concept material is available, whether threat actors are discussing it, or whether active exploitation has been observed. Other contributing factors like EPSS (Exploit Prediction Scoring System) probability, malware associations, ransomware activity, exploit maturity, and threat intelligence can further distinguish an immediate threat from a vulnerability that is technically serious but unlikely to be exploited soon.

Additionally, security teams should also validate whether the vulnerable component is present, whether the affected function is reachable, and whether compensating controls materially reduce the likelihood of exploitation. 

2. Exposure: Can Attackers Reach the Vulnerable Asset?

A CVE becomes more urgent when the affected service is discoverable and reachable from the internet. External attack surface management can identify whether the CVE is associated with an exposed IP address, domain, subdomain, cloud service, VPN appliance, login portal, or unmanaged asset. It can also reveal shadow IT and forgotten infrastructure that may not appear in the organization’s internal asset inventory.

This matters because a patch cannot be prioritized correctly if the security team does not know where the vulnerable asset is or how attackers can reach it. 

3. Business Context: What Happens If It Is Exploited?

The final layer connects technical risk to business consequences. CISOs need to know whether an affected asset supports critical operations, stores sensitive information, processes customer data, or provides access to privileged systems.

Asset ownership, data sensitivity, operational importance, compensating controls, and regulatory impact should influence remediation urgency. A CVE affecting a revenue-critical production service should not sit in the same queue as an identical CVE on a low-impact development asset. In order to detect the relevant CVEs with the right context, CISOs need to integrate vulnerability management tools with their existing security workflow.

How Agentic AI Can Turn Vulnerability Intelligence Into Informed Decisions

Agentic AI-powered vulnerability management tools can continuously correlate data that analysts would otherwise review across multiple tools. An agentic module can correlate CVE severity, KEV status, exploit availability, attacker activity, asset exposure, technology fingerprints, identity relationships, business criticality, and remediation history in one attack path. Instead of simply generating another risk score, an agentic workflow can explain why a vulnerability matters, its business and operational impact, and recommend the next action.

Attack path mapping adds another critical dimension to the vulnerability management process. It shows how an attacker could move from an exposed vulnerability to identities, applications, data stores, or other high-value assets. This helps security teams identify the CVEs that enable meaningful attacker progression over vulnerabilities with high technical severity but limited practical risk.

Agentic AI can then support the operational workflow by grouping duplicate findings, identifying affected owners, recommending remediation priorities, generating tickets, tracking SLA progress, and validating whether exposure remains after remediation.

Although agentic AI simplifies the vulnerability intelligence workflow, human oversight remains essential, particularly for disruptive patches and business-critical systems. The value of agentic AI lies in accelerating correlation and decision support, not removing accountability.

How RiskProfiler Streamlines the Vulnerability Management Process with Contextual Analysis

RiskProfiler is an agentic AI-powered threat intelligence platform that helps CISOs and enterprise security teams prioritize vulnerabilities through a correlated view of vulnerability threat intelligence, the external attack surface, and third-party exposure. Its vulnerability intelligence module presents a consolidated view of all relevant vulnerabilities, adds exploitability context, and provides affected asset context, enabling teams to look beyond CVSS and focus on risks associated with active exploitation, available exploits, and meaningful attacker interest.

The platform’s external attack surface management capabilities help teams discover internet-facing assets and map vulnerabilities to exposed domains, IP addresses, services, cloud infrastructure, and unmanaged technology. Its correlation and attack path mapping help reveal how an exposed weakness could provide access to critical systems, sensitive assets, or identities. This gives remediation teams clearer evidence of why a vulnerability should take precedence over thousands of competing findings.

RiskProfiler also extends this approach to third-party risk management. CISOs and enterprise security teams can assess whether critical third parties use exposed or vulnerable technologies and evaluate the potential business impact of vendor-side weaknesses. This is increasingly important when an organization’s attack surface includes suppliers, SaaS providers, service providers, and other external dependencies it does not directly control.

Enabling Agentic Vulnerability Intelligence for Measurable Risk Reduction

The objective of vulnerability threat intelligence should not be to close the largest number of findings. It should be to interrupt the attack paths most likely to produce business impact. As CVE volumes continue to rise, CISOs need to replace severity-only queues with context-driven prioritization. Exploitability indicates whether attackers are likely to act. Exposure shows whether they can reach the asset. Business context determines what the organization stands to lose.

Combining these signals through Agentic AI-powered vulnerability management tools like RiskProfiler, with continuous correlation and attack path mapping, helps security teams patch fewer vulnerabilities with greater confidence and remediate the right vulnerabilities faster.

Source: 

NIST Update 2026: https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth

Verizon DBIR 2026: https://www.verizon.com/business/resources/reports/dbir/ 



The challenge in the vulnerability intelligence process has shifted from finding vulnerabilities to prioritizing the right ones before attackers exploit them. In 2025, NIST enriched nearly 42,000 Common Vulnerabilities and Exposures (CVEs), which is a 45% increase over any previous year. Yet even this record output could not keep pace with submissions. CVE submissions increased 263% between 2020 and 2025, while submissions in the first quarter of 2026 were nearly one-third higher than during the same period in 2025.

This massive increase in the number of enriched CVEs in NIST's National Vulnerability Database (NVD) makes the vulnerability management process more challenging for enterprise security teams. The higher number of CVEs means increased critical and exploitable exposures for security teams to prioritize, which can overwhelm even a well-resourced security team very fast without any positive result to show.  

Key Takeaways: 

  • Rising CVE volumes make severity-only prioritization unsustainable.

  • Prioritize vulnerabilities using exploitability, internet exposure, business impact, and attack path context.

  • Agentic AI correlates these signals to help security teams remediate the most consequential vulnerabilities faster.

The NIST CVE Enrichment Volume Is Growing Faster Than Traditional Triage Can Scale

In its latest update published in April 2026, NIST has announced that they are bringing changes to its NVD operations. They are now adopting a risk-based enrichment model to adjust to the growing volume of vulnerability submissions, which demonstrates the scale of the problem. Rather than immediately enriching every published CVE, NIST will prioritize vulnerabilities that:

  • Appear in CISA’s Known Exploited Vulnerabilities catalog

  • Affect software used by the US federal government

  • Affect critical software as defined under Executive Order 14028

Other submitted CVEs will remain available in the National Vulnerability Database but may be categorized as lowest priority and not scheduled for immediate enrichment. NIST has also moved older backlogged vulnerabilities into a “Not Scheduled” category while it develops more sustainable automated workflows.

The new enrichment model is adopted to prioritize the critical vulnerabilities. However, it does not imply that other listed vulnerabilities are not important. This update brings a significant change to how CISOs view CVEs and how they prioritize vulnerability patches. With increased CVE volume, enterprise security programs face the same constraint. Teams cannot patch everything simultaneously, and treating every critical CVSS score as an emergency often creates more activity without effective reduction of breach risk. Thus, CISOs need to shift their focus to impact-based vulnerability prioritization for faster detection and response. 

Why CVSS-First Prioritization Creates a False Sense of Urgency

CVSS scores are valuable for measuring the technical severity of a vulnerability, but do not show how it affects the organization's systems or its impact on security, operations, or business continuity. A critical vulnerability on an isolated test server might pose significantly less risk than a mid-severity flaw on an exposed identity system.

This is why CISOs must learn to prioritize CVEs using attack path context, exploitability, exposure, and business impact. This will effectively reduce the number of vulnerabilities to work with, while improving the team’s chances of patching the critical ones before exploitation begins.

Vulnerability Exploitation Is Becoming a Primary Entry Point

The need for contextual prioritization is reinforced by the 2026 Verizon Data Breach Investigations Report. According to their latest release, exploitation of software vulnerabilities accounted for 31% of known initial access vectors, making it the most common entry point in the dataset. 

The challenge of effective vulnerability patching is further highlighted by the report, which also highlights a steep remediation gap. Only 26% of critical vulnerabilities listed in the CISA KEV catalog were fully remediated during 2025. Median time to full resolution increased to 43 days, which was almost two weeks longer than in 2024.

This disparity between the rising CVE volume and declining patching rates presents a concerning picture for the CISOs and enterprise security teams and their security teams. Attackers are increasingly using vulnerabilities for initial access, while organizations are taking longer to resolve vulnerabilities already known to be exploited. It is clear that only adding more findings to a dashboard will not close this gap. Security teams need a prioritization model based on exploitability, exposure, and business impact.

How to Manage Vulnerability Volume Rise with Efficient Prioritization?

In order to prioritize vulnerabilities, CISOs need contextual information that can help them separate noise from relevant intelligence. In this section, we will be highlighting the three primary context layers that help CISOs prioritize vulnerabilities for more effective and time-efficient patch management.

1. Exploitability: Can attackers use the vulnerability now?

In a threat and vulnerability management workflow, exploitability analysis needs to move beyond theoretical severity. It should consider whether a CVE appears in the CISA KEV catalog, whether exploit code or proof-of-concept material is available, whether threat actors are discussing it, or whether active exploitation has been observed. Other contributing factors like EPSS (Exploit Prediction Scoring System) probability, malware associations, ransomware activity, exploit maturity, and threat intelligence can further distinguish an immediate threat from a vulnerability that is technically serious but unlikely to be exploited soon.

Additionally, security teams should also validate whether the vulnerable component is present, whether the affected function is reachable, and whether compensating controls materially reduce the likelihood of exploitation. 

2. Exposure: Can Attackers Reach the Vulnerable Asset?

A CVE becomes more urgent when the affected service is discoverable and reachable from the internet. External attack surface management can identify whether the CVE is associated with an exposed IP address, domain, subdomain, cloud service, VPN appliance, login portal, or unmanaged asset. It can also reveal shadow IT and forgotten infrastructure that may not appear in the organization’s internal asset inventory.

This matters because a patch cannot be prioritized correctly if the security team does not know where the vulnerable asset is or how attackers can reach it. 

3. Business Context: What Happens If It Is Exploited?

The final layer connects technical risk to business consequences. CISOs need to know whether an affected asset supports critical operations, stores sensitive information, processes customer data, or provides access to privileged systems.

Asset ownership, data sensitivity, operational importance, compensating controls, and regulatory impact should influence remediation urgency. A CVE affecting a revenue-critical production service should not sit in the same queue as an identical CVE on a low-impact development asset. In order to detect the relevant CVEs with the right context, CISOs need to integrate vulnerability management tools with their existing security workflow.

How Agentic AI Can Turn Vulnerability Intelligence Into Informed Decisions

Agentic AI-powered vulnerability management tools can continuously correlate data that analysts would otherwise review across multiple tools. An agentic module can correlate CVE severity, KEV status, exploit availability, attacker activity, asset exposure, technology fingerprints, identity relationships, business criticality, and remediation history in one attack path. Instead of simply generating another risk score, an agentic workflow can explain why a vulnerability matters, its business and operational impact, and recommend the next action.

Attack path mapping adds another critical dimension to the vulnerability management process. It shows how an attacker could move from an exposed vulnerability to identities, applications, data stores, or other high-value assets. This helps security teams identify the CVEs that enable meaningful attacker progression over vulnerabilities with high technical severity but limited practical risk.

Agentic AI can then support the operational workflow by grouping duplicate findings, identifying affected owners, recommending remediation priorities, generating tickets, tracking SLA progress, and validating whether exposure remains after remediation.

Although agentic AI simplifies the vulnerability intelligence workflow, human oversight remains essential, particularly for disruptive patches and business-critical systems. The value of agentic AI lies in accelerating correlation and decision support, not removing accountability.

How RiskProfiler Streamlines the Vulnerability Management Process with Contextual Analysis

RiskProfiler is an agentic AI-powered threat intelligence platform that helps CISOs and enterprise security teams prioritize vulnerabilities through a correlated view of vulnerability threat intelligence, the external attack surface, and third-party exposure. Its vulnerability intelligence module presents a consolidated view of all relevant vulnerabilities, adds exploitability context, and provides affected asset context, enabling teams to look beyond CVSS and focus on risks associated with active exploitation, available exploits, and meaningful attacker interest.

The platform’s external attack surface management capabilities help teams discover internet-facing assets and map vulnerabilities to exposed domains, IP addresses, services, cloud infrastructure, and unmanaged technology. Its correlation and attack path mapping help reveal how an exposed weakness could provide access to critical systems, sensitive assets, or identities. This gives remediation teams clearer evidence of why a vulnerability should take precedence over thousands of competing findings.

RiskProfiler also extends this approach to third-party risk management. CISOs and enterprise security teams can assess whether critical third parties use exposed or vulnerable technologies and evaluate the potential business impact of vendor-side weaknesses. This is increasingly important when an organization’s attack surface includes suppliers, SaaS providers, service providers, and other external dependencies it does not directly control.

Enabling Agentic Vulnerability Intelligence for Measurable Risk Reduction

The objective of vulnerability threat intelligence should not be to close the largest number of findings. It should be to interrupt the attack paths most likely to produce business impact. As CVE volumes continue to rise, CISOs need to replace severity-only queues with context-driven prioritization. Exploitability indicates whether attackers are likely to act. Exposure shows whether they can reach the asset. Business context determines what the organization stands to lose.

Combining these signals through Agentic AI-powered vulnerability management tools like RiskProfiler, with continuous correlation and attack path mapping, helps security teams patch fewer vulnerabilities with greater confidence and remediate the right vulnerabilities faster.

Source: 

NIST Update 2026: https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth

Verizon DBIR 2026: https://www.verizon.com/business/resources/reports/dbir/ 



Jump to

Share Article

Got Questions?

We Have Answers!

Explore our FAQ to learn more about how RiskProfiler can help safeguard your digital assets and manage risks efficiently.

Enterprise-Grade Security & Trust

Specialized intelligence agents working together toprotect your organization

Ready to Transform

Your Threat Management?

Join hundreds of security teams who trust KnyX to cut through the noise and focus on what matters most.

Book a Demo Today