A look at US-backed NVD, as its parent org NIST scrambles to hire contractors to help clear a backlog of 25K+ vulnerabilities, ~10x the previous high in 2017
www.technologyreview.com/2025/07/11/ 1...
Context & Ripple Effects
NIST's contractor hiring follows an earlier processing shortfall, when it analyzed only 199 of 3,370 CVEs received in a month, and a broader rise in disclosures: more than 40,000 CVEs were reported in 2024. The backlog is therefore a capacity problem in a shared vulnerability-identification system, not an isolated operational delay.
The pressure arrives as the EU's vulnerability database became operational, making the resilience and responsiveness of public vulnerability data infrastructure more consequential.
First-order effects
- NIST must add contractor capacity to work through more than 25,000 pending vulnerabilities, shifting part of the NVD's near-term recovery effort to outside personnel.
- Organizations awaiting NVD analysis of reported vulnerabilities face continued delays until the queue is reduced; the hiring responds to a backlog far above the prior peak.
Second-order effects
- The backlog increases the value of alternative vulnerability-data sources and workflows for security teams that cannot wait for NVD processing, while the operational EU database becomes a more visible point of comparison.
- Contractors with vulnerability-analysis expertise become a direct bottleneck for recovery, reinforcing the staffing strain already evident in NIST's earlier low processing rate.
Third-order effects
- If disclosure volumes continue to outpace public processing capacity, vulnerability databases may need durable prioritization and operating models rather than episodic backlog-clearing efforts.
- The episode points to a broader resilience question for ecosystem cyber defense: critical public security registries depend on sustained funding and specialist capacity even as reporting scales.
The trend: Public vulnerability infrastructure is being forced to adapt its capacity and prioritization as CVE reporting grows faster than centralized analysis pipelines.