NIST's Decision to Prioritize High-Impact Vulnerabilities: A Shift Towards Proactive Risk Management
The National Institute of Standards and Technology (NIST) has recently made a significant change to its approach to cybersecurity vulnerabilities and exposures (CVEs). In response to a 263% surge in CVE submissions between 2020 and 2025, NIST has decided to prioritize the enrichment of CVEs that meet specific criteria, marking a shift towards a more proactive risk management strategy.
This decision is a response to the overwhelming volume of CVE submissions, which has made it challenging for NIST to keep up with the demand. By focusing on high-impact vulnerabilities, NIST aims to ensure that the most critical issues are addressed first, reducing the risk of widespread impact.
The prioritization criteria outlined by NIST include CVEs that appear in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, CVEs for software used within the federal government, and CVEs for critical software as defined by Executive Order 14028. This includes software with elevated privilege, privileged access to networking or computing resources, control over access to data or operational technology, and operations outside of normal trust boundaries with elevated access.
Any CVE submission that doesn't meet these thresholds will be marked as 'Not Scheduled,' indicating that it is not prioritized for enrichment. This approach is a departure from the traditional method of manually enriching new vulnerabilities, which is no longer feasible or effective in today's threat landscape.
The rise in CVE submissions has led to a significant portion of vulnerabilities without a clear path to enrichment for organizations relying on NIST as their authoritative source of CVE enrichment data. This has prompted a call for distributed, machine-speed approaches to vulnerability identification and enrichment, along with a global perspective on risk that acknowledges the interconnected nature of the worldwide software ecosystem.
David Lindner, chief information security officer of Contrast Security, believes that NIST's decision marks the end of an era where defenders could leverage a single government-managed database to assess security risks. He argues that modern defenders must move beyond the noise of total CVE volume and focus their limited resources on the CISA KEV list and exploitability metrics.
This shift towards a more proactive approach to risk management is a necessary evolution in the cybersecurity landscape. By prioritizing high-impact vulnerabilities, NIST is ensuring that the most critical issues are addressed first, reducing the risk of widespread impact. However, this transition may disrupt legacy auditing workflows, requiring organizations to adapt to a new approach to vulnerability management.
In conclusion, NIST's decision to prioritize high-impact vulnerabilities is a significant step towards a more proactive risk management strategy. While it may disrupt traditional workflows, it ultimately matures the industry by demanding that we prioritize actual exposure over theoretical severity. This approach is essential for national resilience and the effective management of cybersecurity risks in the modern threat landscape.