Severity InflationStanding
NVD is marking vendor scores up by more each year, +0.8 in 2026
Updated 12 August 2026 · Timeframe: By CVE publication year (years with >=500 re-scored pairs)
When NVD re-scores a vendor's CVE it almost always raises it, and the size of that upward correction is growing. It held near +0.5 through 2022-24, then jumped in the last two years. Vendors are diverging from NVD's reading of severity, not converging on it.
Why it matters
Either vendors are under-scoring more as CVE volume rises, or NVD now re-touches only the cases it most disagrees with. Either way, the vendor number and the NVD number are drifting apart.
What to do
- Security leaders. If you standardized on vendor CVSS years ago, revisit it; the gap to NVD's reading is widening.
- Lean IT orgs. Expect the vendor score to understate severity more than it used to.
- MSPs. A growing vendor-vs-NVD gap is a reason to standardize clients on one scoring source, consistently.
Our take
Tracking the drift between who scores a vulnerability is the kind of second-order signal that separates reading the data from reciting it.
The data behind this