Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Threat Intelligence - NIST Declares CVE Cutoff: Pre-2018 Vulnerabilities Now ‘Deferred’
Threat Intelligence Latest News News & Analysis Risk Management Threats and Vulnerabilities

NIST Declares CVE Cutoff: Pre-2018 Vulnerabilities Now ‘Deferred’

Kirsten DoyleBy Kirsten DoyleApril 8, 2025Updated:April 9, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
NIST Declares CVE Cutoff
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The National Institute of Standards and Technology (NIST) has announced that all CVEs published before 1 January 2018, will be marked as ‘Deferred’ in the National Vulnerability Database (NVD).   

“All CVEs with a published date prior to 01/01/2018 will be marked as Deferred within the NVD dataset. We are assigning this status to older CVEs to indicate that we do not plan to prioritize updating NVD enrichment or initial NVD enrichment data due to the CVE’s age,” NIST explained 

It added that: “CVEs marked as Deferred will display a banner on their CVE Detail Pages indicating this status.” 

This change will take place over the course of several nights, the Institute said. “We are doing this to provide additional clarity regarding which CVE records are prioritized.” 
 
NIST added that it will continue to accept and review requests to update the metadata provided for these CVE records. “Should any new information clearly indicate that an update to the enrichment data for the CVE is appropriate, we will continue to prioritize those requests as time and resources allow.” 

NIST also said it will prioritize any CVEs that are added to the KEV regardless of status. 

Reallocating Scare Resources 

This move reallocates scarce resources toward emerging threats, said Jason Soroko, Senior Fellow at Sectigo. “It relies on the premise that legacy issues are already well documented and mitigated by routine patch management. For organizations with modern security practices, the strategy sharpens defense against new exploits. Ultimately, the decision is a calculated trade-off.  It minimizes noise and boosts focus, but leaves risk mitigation for legacy systems squarely in the hands of individual organizations.” 

Defensive security teams should not rely solely on external databases but actively identify legacy systems and deferred vulnerabilities, Soroko added. “Prioritize patching where feasible, enforce system hardening, and isolate or segment older systems to minimize exposure. Integrating real-time threat intelligence helps pinpoint when attackers target known weaknesses, allowing teams to act swiftly.” 

An Expected Solution 

Management of vulnerabilities is complex when you consider the diversity and depth of scale that we have in 2025, with most larger organizations having hundreds to thousands of apps and associated patches across legacy, cloud, and mobile infrastructure with various dependencies, explained Ken Dunham, Cyber Threat Director at Qualys. “A movement by NIST to mark older vulnerabilities as deferred is an expected evolution of the scale of management of vulnerabilities as they continue to grow in number with the explosion of apps and associated vulnerabilities in 2025.” 

Entities should take this action by NIST as an indicator of the challenge to manage and prioritize their own risk, particularly for high-value assets and any assets with increased exposure to attack surface, Dunham added. “Exploitation often occurs amongst more moderate and older vulnerabilities still in production, requiring more complex patching priorities for organizations to manage vulnerability risk ranging from zero-days and emergent risk to long-term likely exploitation from persistent actors.” 

Dunham says a strong threat and vulnerability patch management program, with strong CMDB, validation of successful patching, KPIs and metrics, risk-based prioritization, and holistic SecOps, are required to address the continual threat and vulnerability management needs of an organization. 

Underperforming Patch Management 

Tim Mackey, Head of Software Supply Chain Risk Strategy at Black Duck, said while it may be concerning to see older CVEs, particularly those associated with prominent vulnerabilities, be triaged to a lower priority, the reality is that the CVE remains in the NVD with a recognition that updates to older CVEs are infrequent. “For practical purposes, I would view any organization who hasn’t patched or mitigated something that is now labeled as “Deferred” as having an underperforming patch management or DevOps cybersecurity program.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}