Connected medical devices have become one of the fastest-growing sources of cyber risk in healthcare, and the vulnerability disclosure pipeline that is supposed to help hospitals manage that risk is straining under its own volume. CVE submissions have risen 263% between 2020 and 2025, the National Vulnerability Database can no longer fully enrich records outside a narrow set of categories, and the medical device firmware and clinical middleware that biomedical engineering teams depend on for accurate scan results increasingly fall outside that coverage entirely. The result is a widening gap between what is disclosed and what hospitals can actually act on.