NIST gives up enriching most CVEs
TL;DR AI
2 min readKey summary
NIST said it will stop enriching most CVEs and will only add extra details for vulnerabilities it deems important.
The policy change means many CVEs may no longer get the added official context security teams rely on.
That could make vulnerability prioritization and triage harder, especially when organizations face large CVE volumes.
NIST’s move narrows its enrichment work to higher-priority cases going forward.



