Empirical Security found that NVD adds its own Patch label to about three in ten of the CVEs it analyzes.
Public source
Publisher name
Public post
The most useful thing in a CVE record is the link to the fix, and almost no CNA labels it. The CVE format lets a CNA tag a reference as "patch". That is how a tool knows…
Company
Empirical Security
Security Intelligence and Decision Support, Tailored to your Enterprise.
- Industry
- Computer and Network Security
- Location
- Chicago, US
- Company size
- 11–50 employees
About Empirical Security
Empirical builds mathematical models for security data. We maintain the world’s most advanced global models for cybersecurity, and we build local models that respond to your enterprise’s specific context and threat landscape.
See moreLatest activity
Latest activity from Empirical Security
14 signals
Research & Knowledge
Empirical Security reported that of the 51,219 CVEs published in 2026 that NVD has settled, 20,076 are marked as Deferred.
Research & Knowledge
Empirical Security published 12% of CVEs in 2026 with the CNA tag.
Research & Knowledge
Empirical Security found that three of the 26 CNAs tagged nearly every record in 2026.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Emphere
Emphere mapped what actually happens between a CVE being disclosed and a fixed image running in production, finding that the median time is about 18 days.
Research & Knowledge
Kai
Kai NIST reported that roughly 48% of this year's CVEs have never been analyzed by the NVD at all.
Research & Knowledge
ReliaQuest
ReliaQuest research points to a new defense timeline with 6,202 high and critical vulnerabilities identified, 90.6% confirmed valid, and a mean time-to-exploit moving to 7 days before public disclosure.
Research & Knowledge
Vicarius
Vicarius analyzed hundreds of organizations across industries to benchmark patch deployment speed and vulnerability remediation time.
Research & Knowledge
Root Evidence