Dossier
Executive Order 14028
Coverage of Executive Order 14028 in the Nexus archive.
- NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
NIST has narrowed its focus for analyzing CVEs to prioritize those in CISA's catalog, federal government software, and critical software under Executive Order 14028 due to an overwhelming increase in vulnerabilities. The change aims to stabilize the NVD program amid backlogs and funding challenges, shifting away from automatically enriching non-priority CVEs.