Cyber Resilience

Score DisagreementWeekly

NVD and the vendor split hardest on CVE-2026-57926: a 7.2-point gap

Updated 12 August 2026 · Timeframe: CVEs published in the last 60 days

CVE-2026-579267.2CVE-2026-88016.3CVE-2026-88006.1CVE-2026-563725.8CVE-2026-24825.7CVE-2026-351425.6
Biggest NVD-vs-vendor CVSS gaps, recent CVEs · security-resilience.ai

Among recently-published CVEs that both NVD and the assigning vendor scored, the widest gap is CVE-2026-57926: the vendor rated it 2.6, NVD 9.8, a 7.2-point markup. The chart shows the biggest current disagreements, cases where your triage answer depends on which database you trust.

Why it matters

A multi-point gap between the vendor and NVD is a triage fork: patch-now under one score, next-window under the other. These are the CVEs to resolve deliberately, not by default.

What to do

Our take

Surfacing where the two authoritative scores actually collide is more useful than either score alone.