Cyber Resilience

Severity Re-scoringStanding

NVD overrules the vendor's severity score on 80% of CVEs, mostly upward

Updated 12 August 2026 · Timeframe: 2025-2026 CVEs scored by both NVD and the vendor

57%20%23%NVD raised the score (10,116, 56.8%)NVD agreed (3,581, 20.1%)NVD lowered it (4,120, 23.1%)
NVD versus the vendor's CVSS score, 2025-26 · security-resilience.ai

When a vendor (a CNA) assigns a CVSS score and NVD later publishes its own, they disagree on 80% of 2025-26 CVEs both scored, and NVD raises the score about 2 times more often than it lowers it (57% up, 23% down). The US re-scoring authority is NVD (NIST), not CISA, and it reads vendors as under-rating impact.

Why it matters

This is the hidden engine behind the EU looking softer on severity. ENISA's EUVD passes the vendor's score through unchanged, so wherever NVD marked a score up, the EU keeps the lower original. The apparent EU-versus-US gap is largely a re-scoring artifact, not a European judgment.

What to do

Our take

A severity number is a vendor's opinion, sometimes overruled by NVD and echoed by the EU. Knowing which number you are holding is the actual skill.

Earlier issues

Past states of this signal, most recent first.

05 August 2026 NVD overrules the vendor's severity score on 80% of CVEs, mostly upward

Timeframe: 2025-2026 CVEs scored by both NVD and the vendor

58%20%22%NVD raised the score (10,034, 58.0%)NVD agreed (3,541, 20.5%)NVD lowered it (3,735, 21.6%)

When a vendor (a CNA) assigns a CVSS score and NVD later publishes its own, they disagree on 80% of 2025-26 CVEs both scored, and NVD raises the score about 3 times more often than it lowers it (58% up, 22% down). The US re-scoring authority is NVD (NIST), not CISA, and it reads vendors as under-rating impact.

30 July 2026 NVD overrules the vendor's severity score on 79% of CVEs, mostly upward

Timeframe: 2025-2026 CVEs scored by both NVD and the vendor

60%21%19%NVD raised the score (9,986, 60.2%)NVD agreed (3,436, 20.7%)NVD lowered it (3,177, 19.1%)

When a vendor (a CNA) assigns a CVSS score and NVD later publishes its own, they disagree on 79% of 2025-26 CVEs both scored, and NVD raises the score about 3 times more often than it lowers it (60% up, 19% down). The US re-scoring authority is NVD (NIST), not CISA, and it reads vendors as under-rating impact.