Research · Explainer

Understanding CVEs: How Vulnerability IDs Work and How to Read Them

A CVE is an identifier, not a verdict. Here is how IDs are assigned, what the NVD adds on top, and why the same flaw can carry two different severity scores.

An aerial view of the National Institute of Standards and Technology campus in Gaithersburg, Maryland. NIST runs the National Vulnerability Database (NVD).
An aerial view of the National Institute of Standards and Technology campus in Gaithersburg, Maryland. NIST runs the National Vulnerability Database (NVD), which enriches published CVE records with severity and weakness data.

Photo: Antony-22, CC BY-SA 4.0, via Wikimedia Commons

Every major patch cycle — from Cisco’s NX-OS advisories to SonicWall’s hotfix notices — arrives with a string that looks like CVE-2026-76485. That string is the spine of vulnerability management. Here is what it means, who mints it, and how to read what comes with it.

What a CVE is

“The mission of the CVE™ Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog,” according to cve.org. A CVE ID is simply a unique identifier — CVE-YYYY-NNNNN, the year of assignment plus a sequence number — so that vendors, researchers, and defenders can all refer to the same flaw without ambiguity.

What a CVE is not: a severity score, a patch, or a judgment about risk. The identifier and the assessment are separate things, maintained by separate organizations. The CVE Program itself does not assign severity scores — cve.org’s myths-vs-facts page explicitly lists “Myth #4: The CVE Program is responsible for assigning vulnerability severity scores.”

Who assigns IDs

Assignment is decentralized. Vulnerabilities are “discovered then assigned and published by organizations from around the world that have partnered with the CVE Program” — these partners are CVE Numbering Authorities (CNAs), organized under Roots and Top-Level Roots, and there is no fee to participate as a CNA.

In practice, CNAs include major vendors — Cisco and SonicWall assign IDs for their own products — as well as coordinators and research organizations. A single flaw gets one ID no matter how many vendors ship the affected component, which is why one CVE can appear in several vendors’ advisories at once.

The NIST campus in Gaithersburg, Maryland.
The NIST campus in Gaithersburg, Maryland. The NVD does not perform its own vulnerability testing; it relies on vendors, researchers, and coordinators.

Photo: Owenusa, Public domain, via Wikimedia Commons

What the NVD adds

The National Vulnerability Database, run by NIST’s Computer Security Division, is “the U.S. government repository of standards based vulnerability management data,” per nvd.nist.gov. The NVD enriches each published CVE with CVSS impact metrics, CWE weakness types, and CPE applicability statements — the severity score, the weakness category, and the list of affected products.

Two important caveats from NIST itself: “The NVD does not actively perform vulnerability testing, relying on vendors, third party security researchers and vulnerability coordinators to provide information that is then used to assign these attributes,” and CVSS assessments “are subject to change” as information evolves.

How to read an NVD entry

Open any CVE record on nvd.nist.gov and you will find four things worth reading:

  1. The description — what the flaw is, in plain terms, and what an attacker can do with it.
  2. The CVSS vector and base score — the severity number (0.0–10.0) and the vector string that encodes how it was calculated. The vector matters more than the number: two flaws scoring 9.8 can differ wildly in exploitability.
  3. The CWE — the weakness category (for example, CWE-121, stack-based buffer overflow), useful for pattern-spotting across advisories.
  4. The references — links to the vendor advisory, researcher write-ups, and any exploit reports. Always click through to the vendor advisory before acting.

Why scores differ between vendors and the NVD

A vendor advisory may rate a flaw 9.3 while the NVD later lists 9.8, or vice versa. That is normal, not an error. Vendors score for their product in its intended deployment; the NVD scores the underlying vulnerability generically, and both may revise as new information arrives. When scores disagree, treat the vendor’s environmental guidance and the NVD’s base score as complementary inputs — and verify against the advisory itself before republishing a number.

Why some flaws have no CVE

Not every security problem is a software vulnerability. The FortiBleed campaign — a global credential-harvesting operation against FortiGate firewalls — carries no CVE by nature: it abuses reused credentials and legacy password storage, not a flaw in code. No new identifier is issued because there is no new vulnerability to catalog. When a story names no CVE, check the mechanism before assuming one was missed.

No corrections have been published for this article.

About the author

Devon Cross, Correspondent — beat: vulnerabilities & security research.