Severity Re-scoringStanding
NVD overrules the vendor's severity score on 80% of CVEs, mostly upward
Updated 12 August 2026 · Timeframe: 2025-2026 CVEs scored by both NVD and the vendor
When a vendor (a CNA) assigns a CVSS score and NVD later publishes its own, they disagree on 80% of 2025-26 CVEs both scored, and NVD raises the score about 2 times more often than it lowers it (57% up, 23% down). The US re-scoring authority is NVD (NIST), not CISA, and it reads vendors as under-rating impact.
Why it matters
This is the hidden engine behind the EU looking softer on severity. ENISA's EUVD passes the vendor's score through unchanged, so wherever NVD marked a score up, the EU keeps the lower original. The apparent EU-versus-US gap is largely a re-scoring artifact, not a European judgment.
What to do
- Security leaders. Do not treat a vendor's CVSS as final; expect NVD to read a share of them as more severe, concentrated in the impact metrics.
- Lean IT orgs. If you triage off vendor or EU scores, add a check against the NVD score for anything near a decision boundary.
- MSPs. When a client's scanner and the NVD number disagree, the usual cause is a vendor-versus-NVD re-score, not a data error.
Our take
A severity number is a vendor's opinion, sometimes overruled by NVD and echoed by the EU. Knowing which number you are holding is the actual skill.
Earlier issues
Past states of this signal, most recent first.
05 August 2026 NVD overrules the vendor's severity score on 80% of CVEs, mostly upward
Timeframe: 2025-2026 CVEs scored by both NVD and the vendor
When a vendor (a CNA) assigns a CVSS score and NVD later publishes its own, they disagree on 80% of 2025-26 CVEs both scored, and NVD raises the score about 3 times more often than it lowers it (58% up, 22% down). The US re-scoring authority is NVD (NIST), not CISA, and it reads vendors as under-rating impact.
30 July 2026 NVD overrules the vendor's severity score on 79% of CVEs, mostly upward
Timeframe: 2025-2026 CVEs scored by both NVD and the vendor
When a vendor (a CNA) assigns a CVSS score and NVD later publishes its own, they disagree on 79% of 2025-26 CVEs both scored, and NVD raises the score about 3 times more often than it lowers it (60% up, 19% down). The US re-scoring authority is NVD (NIST), not CISA, and it reads vendors as under-rating impact.