MEDIUMVulnerability
Verified
United States

NIST NVD Backlog Exceeds 30,000 Unanalyzed CVEs

Friday, March 20, 2026 at 09:00 AM UTC·Source: Cybersecurity Coalition

Updated: Saturday, March 21, 2026 at 03:00 PM UTC

Executive Summary

NVD backlog doubles year-over-year, creating blind spots in vuln management. Industry coalition demands congressional emergency funding.

Analysis

Over 30,000 CVEs lack CVSS scores and CPE data. Security teams increasingly relying on VulnCheck, OSV, and vendor advisories. Particularly impactful for healthcare and government compliance requirements. CISA Vulnrichment program helping but incomplete.

Timeline

Discovered
Feb 1, 2025
Published
Mar 20, 2026
Source Attribution

Originally published by Cybersecurity Coalition on Mar 20, 2026. Verified by: NIST, CISA.

Related Threats