NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities

2026-04-16T14:52:23Zd1a1ed880ea094903d9409c4f0fdbde61caf276ea7303d07ba55bc61a2d5496f
AV-killAnthropicApache ActiveMQCISACVE programCVE-2026-33032CVSS 9.8ENISAFortinetGPUBreachMCP protocolMicrosoftMirax TrojanNISTNVDNinja FormsOpenAIRowhammerSTX RATactive exploitationadwaremailbox-rule-abusemalicious Chrome extensionsnginx-uizero-day

What happened

A broad set of security stories: NIST’s NVD will deprioritize enrichment for vulnerabilities reported before March 2026 to focus resources on newly reported and actively exploited CVEs amid record CVE volume. A systemic MCP protocol flaw and a critical nginx‑ui MCP authentication‑bypass (CVE-2026-33032, CVSS 9.8) are highlighted as actively exploited; Ox Security estimates large exposure for MCP and exploitation is ongoing. Multiple zero‑day and high‑severity incidents prompted emergency fixes (Fortinet FortiClient EMS; Microsoft patched two zero‑days), while large scale campaigns and threats—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
d1a1ed880ea094903d9409c4f0fdbde61caf276ea7303d07ba55bc61a2d5496f
Enrichment time
2026-04-16T14:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.