The greatest documentarians of computer vulnerabilities are completely overwhelmed and cannot keep up with the security holes, given the speed at which they are occurring. This is the main conclusion of the statement sent by the U.S. National Institute of Standards and Technology (NIST). The agency has announced that from now on they will only add details and information to those records of failures that meet certain criteria. To date, the NIST had strictly fulfilled its mission to catalog all CVEs (common vulnerabilities and exposures) as they occurred. The agency was responsible for adding descriptions and data to each failure after being listed in the National Vulnerability Database (NVD). However, the avalanche of new entries has made this task impossible for its staff. It is known that only 21 people are working on monitoring and documenting these bugs. The volume of vulnerabilities has increased massively in recent years. From 2020 to 2025, CVE submissions grew by 263%. And this year, the situation has escalated even more. "Requests during the first three months of 2026 are almost a third higher than those in the same period last year. We are working faster than ever... but it is not enough to keep up," the agency acknowledged. Selective with the 'enrichments' Therefore, NIST has decided to be selective with the 'enrichments'. This term refers to those vulnerabilities that receive additional information after being identified. Just last year, 42,000 entries were 'enriched'. Thus, although new CVEs will be incorporated into the list, only those failures actively exploited by the CISA agency, flaws in software used by the federal government, and vulnerabilities in programs considered critical will be updated. With these filters, some streamlining is expected. The idea is to be able to provide additional information on the most critical security issues within 24 hours.
NIST overwhelmed by surge in <b>cybersecurity</b> vulnerabilities | DigitalShield
Read the original article
escudodigital.com →