A Quantum Risk Index for Cryptographic CVEs: Empirical Evidence from the National Vulnerability Database, 2016–2026
Evgeniya Ishchukova, Faezeh Sadat Sajadi, Sergei Petrenko, Alexey Petrenko, Alexey NekrasovThe harvest now, decrypt later (HNDL) attack is an attack that collects encrypted information now and decrypts it later after the arrival of a quantum computer that can perform some cryptographic operations. Time of exposure is data retention and not Q-Day, so the threat is imminent, but it is not reflected in the Common Vulnerability Scoring System (CVSS). We present the Quantum Risk Index (QRI), which is based on CVSS base severity, the Quantum Factor (QF, vulnerability to Shor’s or Grover’s algorithm), and the HNDL Score (HS, susceptibility to a harvest-and-store adversary). We computed the QRI for 78,587 CVEs that were cataloged in the NIST National Vulnerability Database between January 2016 and the first quarter of 2026 and cross-checked it with the CISA Known Exploited Vulnerabilities (KEV) list. The number of CVEs related to cryptography increased by a CAGR of 11.0%, while the number of Shor-vulnerable CVEs increased at a CAGR of 8.8%. The 437 KEV-matched CVEs carry a mean QRI of 13.05, against 10.31 for the non-KEV remainder—a 26.6% separation (p = 2.17 × 10−63)—and Shor-vulnerable CVEs appear in the KEV list at 1.52 times the baseline rate (p = 0.002). This separation is valid for each of the tested settings of QF and HS. This is the first study to apply a quantum-adjusted vulnerability score to a government’s in-the-wild vulnerability reporting database at the CVE scale, providing a repeatable foundation for quantum-aware vulnerability triage.