Patterns of CNA behavior for April 2026 worth noting

Date | Distinct CVEs touched | Messages | Driver |
|---|---|---|---|
2026-04-01 | 10,164 | 134,930 | Patchstack CVSS wipeout (corrects prior memory date) |
2026-04-08 | 9,404 | 33,123 | Wordfence mass enrichment (NOT Patchstack) |
2026-04-13 | 1,182 | 11,337 | mixed CNAs |
2026-04-23 | 9,334 | 103,279 | Patchstack CVSS restoration |
2026-04-27 | 1,443 | 20,940 | Patchstack continuation |
2026-04-28 (today, ongoing) | 4,551 | 39,174 | Patchstack continuation |
CNA | CVEs touched | Adds | Removes | Replaces | Pattern |
|---|---|---|---|---|---|
Patchstack | 12,890 | 106,409 | 109,438 | 34,210 | Wipe → Restore cycle (mostly add≈remove pairs) |
Wordfence | 9,086 | 10,652 | 98 | 11,387 | Heavy |
VulDB | 774 | 42,771 |
2026-04-01 (THE wipeout, not Apr 8): 7,286 CVEs lost their CVSS metric blocks in one bulk update. Specific field removes:
containers/cna/metrics/0/cvssV3_1/{baseScore,baseSeverity,attackVector,attackComplexity,privilegesRequired,userInteraction,confidentialityImpact,integrityImpact,availabilityImpact} — 7,286 eachcontainers/cna/source — 7,287 removes (entire metric source block also dropped)2026-04-23 (restoration): 8,389 CVEs got CVSS added back. Of 7,122 paired against pre-wipe values: 99.5% identical, 0.5% genuinely rescored. (Already analyzed in detail.)
2026-04-27/28 (ongoing): ~15K more CVEs being touched. The pattern (CNA-side adds, ADP-side removes) suggests they are now also restoring/cleaning the CISA-ADP layer that was orphaned during the wipe.
8,844 CVEs touched on a single day. Replace-dominant: 8,753 replaces on containers/cna/affected/0, plus reference and description rewrites. Pattern is consistent with rebuilding the affected-product representation (e.g., switching schema for plugin/version ranges) — not rescoring.
774 CVEs, 42,771 pure adds, 4 removes. Fields added are not CVSS 3.1 base fields but the CVSS 4.0 / Temporal-Threat layer:
reportConfidence, remediationLevel, exploitCodeMaturity, exploitMaturity, exploitabilityattackVector, attackComplexity, etc.) — likely new CVSS 4.0 vectors alongside existing CVSS 3.1This is enrichment, not correction — VulDB is publishing the threat-environmental layer that most CNAs ignore.
1,279 CVEs touched (Apple's normal cadence is dozens, not thousands). Operations dominated by replace on descriptions/0, affected/0..3, and references/0..3. This is a bulk re-publication of historical Apple advisories, possibly tied to a CNA tooling migration. Not new CVEs, no severity changes — purely structural.
remove events on Apr 27–28 indicate the orphaned CISA enrichment layer is now being torn down and republished now that the CNA-layer is stable.4
79 |
Pure add — CVSS 4.0 / threat-metrics rollout |
GitHub_M | 1,355 | 25,336 | 221 | 103 | Normal cadence |
apple | 1,279 | 1,502 | 1,475 | 2,667 | Bulk product/desc/refs rewrite |