news.mlab.sh
Back to the feed
threat-intel

Inspector general finds NIST mistakes have made vulnerability database ineffective

High
Summary

A recent inspector general report has identified significant mismanagement and strategic failures within the National Institute of Standards and Technology (NIST)’s National Vulnerability Database (NVD), resulting in a massive backlog of unprocessed security vulnerabilities. The backlog, which grew from 13,000 to over 27,000 by the end of 2025, undermines the database’s utility and public trust, largely due to a lack of planning, duplicated efforts with CISA, and ineffective communication. NIST acknowledges the issues and has committed to implementing changes, but the report highlights the urgent need for sustainable processes and collaboration.

The core issue stems from NIST’s failure to adequately manage the NVD’s processing workflow. Initially, the agency ceased paying contractors responsible for reviewing vulnerabilities, triggering a rapid backlog. Despite pledging to address the problem by September 2024, NIST failed to meet its goals of processing approximately 6,200 vulnerabilities monthly, a rate it had never previously achieved. This mismanagement was compounded by a lack of strategic planning and a failure to coordinate with CISA, leading to duplicated efforts and wasted resources. The report details instances where both agencies hired the same contractors to perform identical tasks, further exacerbating the problem.

The inspector general’s findings also point to a critical communication breakdown. A letter from 50 cybersecurity professionals to Congress and the Secretary of Commerce went unanswered by NIST or the Department of Commerce, highlighting concerns about transparency. Furthermore, NIST’s approach to assigning severity scores was deemed largely ineffective, with 80% of submissions already including scores and only 12% aligning with independent assessments. NIST is now implementing changes to address these shortcomings, including a shift in focus away from severity scoring and a renewed commitment to collaboration with CISA.

Read the full article at The Record