Score DisagreementWeekly
NVD and the vendor split hardest on CVE-2026-57926: a 7.2-point gap
Updated 12 August 2026 · Timeframe: CVEs published in the last 60 days
Among recently-published CVEs that both NVD and the assigning vendor scored, the widest gap is CVE-2026-57926: the vendor rated it 2.6, NVD 9.8, a 7.2-point markup. The chart shows the biggest current disagreements, cases where your triage answer depends on which database you trust.
Why it matters
A multi-point gap between the vendor and NVD is a triage fork: patch-now under one score, next-window under the other. These are the CVEs to resolve deliberately, not by default.
What to do
- Security leaders. For split-score CVEs, decide which authority you follow and apply it consistently, not case by case.
- Lean IT orgs. Where the vendor and NVD disagree by 2+ points, default to the higher score until you can check the vector.
- MSPs. A wide vendor-vs-NVD gap is worth a proactive note to clients running the affected product.
Our take
Surfacing where the two authoritative scores actually collide is more useful than either score alone.
The data behind this