Inspector general finds NIST mistakes have made vulnerability database ineffective

2026-06-01T20:52:22Z9779bccce70e8e84c05cb5367785afcb70bcaaa675fa10e13d842ca956016f7c
AfghanistanMicrosoftNISTNSANVDPakistan-linkedRussiaSideCopycyberespionagecybersecurity policyinspector generalleadership changemaritime universitiesnon-prosecutionpublic trustsecurity researcherstargeted attacksunknown hacking groupvulnerability backlogvulnerability managementzero-day disclosure

What happened

Multiple cybersecurity developments: A U.S. Office of Inspector General report found NIST errors allowed the National Vulnerability Database (NVD) backlog to grow from ~13,000 unprocessed vulnerabilities in Feb 2024 to over 27,000 by end of 2025, undermining the NVD’s utility and public trust. The NSA named David Imbordino as its new cybersecurity chief and Bruce Jones to lead its Cybersecurity Collaboration Center. Microsoft said it will not pursue legal action against security researchers after backlash over handling of zero-day disclosures. Separately, researchers attributed a suspected Pak

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
9779bccce70e8e84c05cb5367785afcb70bcaaa675fa10e13d842ca956016f7c
Enrichment time
2026-06-01T20:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Inspector general finds NIST mistakes have made vulnerability database ineffective · Baitaphish