There’s an assumption baked into most vulnerability management programs that nobody ever wrote down, because nobody had to. When a CVE gets published, NVD enriches it. You get a severity score, product mappings, weakness categorization. All the context your tools and workflows need to actually do something. It was just how the system worked. In..
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/the-end-of-centralized-enrichment-what-nists-nvd-shift-means-for-vulnerability-management/
![]()

