Cyber Resilience

Severity InflationStanding

NVD is marking vendor scores up by more each year, +0.8 in 2026

Updated 12 August 2026 · Timeframe: By CVE publication year (years with >=500 re-scored pairs)

20182026000
Average NVD-minus-vendor CVSS correction, by year · security-resilience.ai

When NVD re-scores a vendor's CVE it almost always raises it, and the size of that upward correction is growing. It held near +0.5 through 2022-24, then jumped in the last two years. Vendors are diverging from NVD's reading of severity, not converging on it.

Why it matters

Either vendors are under-scoring more as CVE volume rises, or NVD now re-touches only the cases it most disagrees with. Either way, the vendor number and the NVD number are drifting apart.

What to do

Our take

Tracking the drift between who scores a vulnerability is the kind of second-order signal that separates reading the data from reciting it.