NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities
2026-04-16T14:52:23Z•d1a1ed880ea094903d9409c4f0fdbde61caf276ea7303d07ba55bc61a2d5496f
AV-killAnthropicApache ActiveMQCISACVE programCVE-2026-33032CVSS 9.8ENISAFortinetGPUBreachMCP protocolMicrosoftMirax TrojanNISTNVDNinja FormsOpenAIRowhammerSTX RATactive exploitationadwaremailbox-rule-abusemalicious Chrome extensionsnginx-uizero-day
What happened
A broad set of security stories: NIST’s NVD will deprioritize enrichment for vulnerabilities reported before March 2026 to focus resources on newly reported and actively exploited CVEs amid record CVE volume. A systemic MCP protocol flaw and a critical nginx‑ui MCP authentication‑bypass (CVE-2026-33032, CVSS 9.8) are highlighted as actively exploited; Ox Security estimates large exposure for MCP and exploitation is ongoing. Multiple zero‑day and high‑severity incidents prompted emergency fixes (Fortinet FortiClient EMS; Microsoft patched two zero‑days), while large scale campaigns and threats—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- d1a1ed880ea094903d9409c4f0fdbde61caf276ea7303d07ba55bc61a2d5496f
- Enrichment time
- 2026-04-16T14:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.