Security1 distinct publisher2 min readPublished
Those records now carry the status Not Scheduled with no published completion target, so any prioritization pipeline keyed to an NVD base score will read them as absent rather than unscored. The fallback has to be built locally.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
"Not Scheduled" is a status field, not a severity judgment. The effect lands one layer down, in the join. Most prioritization stacks ask NVD two questions about a CVE: what is the base score, and which products does it affect. Remove both and the record does not surface as low risk [3]. It surfaces as absent, or as unknown, and unknown does not open tickets by itself.
The population is at least bounded. Every record in the set was published before March 1, 2026, so the set is closed and cannot grow [2][4]. That makes it a backfill problem rather than a permanent stream. What the source does not supply is a completion target, or the criteria by which a record leaves Not Scheduled, which means a team cannot tell today whether a given CVE is queued or parked [10]. NIST's own wording is not quoted in the piece; the statement is described as an April update to NVD operations, made in response to CVE volume outgrowing the enrichment model [1].
The sizing of the pressure comes from one interested party. The article is bylined by Gene Moody, Field CTO at Action1 [11], and the volume figures are from Action1's own 2026 Software Vulnerability Ratings Report: disclosures across the enterprise categories analyzed up 92% in 2025 over 2024, critical and high each up 103%, remote code execution up 128% [4][5][6]. That is a shade under double year over year [1], with the RCE subset growing 36 points faster than the whole [2]. The same report puts enterprise application exploitation up 800%, about nine times the prior year [7][3]. No independent corroboration appears in the source.
Where this does not matter much: for a vulnerability you are actually chasing, the vendor advisory arrived before NVD enrichment ever would have. Moody's own argument is that attackers correlate vendor advisories, research, patch releases and public disclosure without waiting for standardized fields [8]. Defenders read the same feeds. What the 30,000 lose is normalization, and normalization is what automation consumes.
Where it does matter: affected-product data. Incomplete or overly broad CPE pushes false positives up, and false positives are paid in analyst hours [9]. Moody expects organizations to build alternative intelligence pipelines, with the cost, tooling and operational complexity that implies, and higher failure rates with it [13]. For the 30,000 that leaves two workable positions: substitute a severity source the team controls and label the substitution, or make unscored its own queue that a human triages.
Ranked by verification strength, evidence, and original report placement.
NVD enrichment supplies structured metadata, affected-platform information, severity scoring and configuration details that let defenders judge whether a vulnerability applies to their environment and how urgently to address it.
The article is authored by Gene Moody, Field CTO at Action1, and published by BleepingComputer, and it links to Action1's own report.
Because membership in the Not Scheduled set is defined by a publication date before March 1, 2026, the set is closed and cannot grow with future disclosures.
NIST released a statement in April on updates to NVD operations, described as a response to scale, because CVE volume has grown beyond what the current enrichment model was designed to handle.
As part of the change, roughly 30,000 vulnerabilities published before March 1, 2026 were reclassified as "Not Scheduled".
Action1's 2026 Software Vulnerability Ratings Report found disclosed vulnerabilities across the enterprise software categories analyzed increased 92% in 2025 compared with 2024.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
build
Firmware CVE intake: the finding is almost never a zero-day, it is a five-year-old BusyBox1 distinct publisher
security
The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation1 distinct publisher
build
Calix gateway takes UPnP orders from the internet, and there is no patch to install1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One byline, one interested source
Everything traceable here passes through a single guest column, and its two most consequential facts — NIST's April statement and the roughly 30,000 records now marked Not Scheduled — are paraphrased rather than quoted or linked to primary text. The four growth percentages all come from the author's employer's report, with no counts, category list or methodology attached. The 30,000 figure and the March 1, 2026 cutoff are specific enough to verify in minutes; in this reporting, nobody has.
The database moved; its consumers are unobserved
Something concrete has happened on one side of this: a status was applied to tens of thousands of records in a dataset that scanners, ticket queues and severity gates read automatically, which means the change propagates whether or not anyone noticed. The other side is blank. No scanner vendor, no security team, no tooling changelog appears anywhere in this reporting as having adjusted for unscored records, and the prediction that organizations will build alternative pipelines names no organization that has.
Big percentages over a small, unverified core
The proportions are off in both directions at once. An AI headline sits atop a piece whose actual finding is administrative and far more useful: a bounded set of records with no published completion target, which prioritization logic will read as absent rather than unscored. That gets a paragraph. Meanwhile 800%, 128% and a forecast of "increasing failure rates" get the emphasis, all sourced to the author's own report and none anchored to a baseline. The alarm is louder than the evidence, and the genuinely operational point is quieter than it deserves.
Diagnosis and cure share a payroll
The prescribed fix — lean less on one authoritative feed, correlate vendor advisories, independent vulnerability intelligence and internal asset inventories, and acquire the tooling and process maturity to do it — describes the category the author's employer sells into. Every statistic quoted comes from that employer's report, and a mid-page link invites the reader to go get it. BleepingComputer's audience gets a genuine argument, but the byline is the only disclosure on offer, and the further the writing moves from the NVD status change toward remedies, the more its interests and its conclusions align.
Structure trustworthy, numbers not yet
We would stake something on the shape of this — a dated cutoff, a finite set of records, no committed completion target — because that logic survives regardless of who reports it, and because it is a poor thing to invent. We would stake little on the magnitudes or the consequences until NIST's own statement and a non-Action1 count are in view. A second, disinterested account of the 30,000 records would move this number more than anything else could.