Skip to main content
CybersecurityVulnerability Management

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery

Cybersecurity team works in a busy operations center with multiple screens and computer equipment.

Roughly 30,000 vulnerabilities published before March 1, 2026, were reclassified as "Not Scheduled."

NIST's April change to NVD operations and why it happened

In April, NIST announced operational updates to the National Vulnerability Database (NVD) intended to respond to scale: the volume of CVEs has exceeded the enrichment model the system was built to handle. As part of that shift, roughly 30,000 previously published vulnerabilities were reclassified as "Not Scheduled," an explicit signal that selective processing, prioritization, and automation will be used to manage the backlog.

Disclosure and exploitation metrics from Action1’s 2026 report

Those operational choices arrive against a sharp rise in disclosures and exploitation. Action1’s 2026 Software Vulnerability Ratings Report reported that disclosed vulnerabilities across the enterprise software categories it analyzed increased 92% in 2025 versus 2024. The same report found critical and high‑severity vulnerabilities each rose 103%, vulnerabilities enabling remote code execution rose 128%, and enterprise application exploitation surged 800% in the last year.

Why delayed enrichment becomes operational risk

Enrichment in NVD terms means adding structured metadata—affected‑platform data such as CPEs, severity scoring, configuration details and other context that makes a CVE actionable for defenders. When NVD enrichment is applied primarily to more recent CVEs, that process implicitly deprioritizes older entries that may already be known to vendors or researchers but lack the NVD's normalized context. The result is an asymmetric information environment: defenders who rely heavily on the NVD can see incomplete or delayed data, while attackers can correlate vendor advisories, research, patch releases, exploits and public disclosures without waiting for standardized enrichment.

According to the source material, that gap forces organizations into two difficult choices—wait for additional context, or act on fragmented intelligence—neither of which is ideal when exploitation activity is rising rapidly.

Downstream effects: false positives, tooling drift, and rising costs

A rolling backlog that is continuously fed while being selectively drained creates a semi‑permanent state of uncertainty about coverage. Incomplete or overly broad affected‑product information increases false positives and complicates prioritization: teams may spend time chasing vulnerabilities that do not apply to their estate while overlooking those that do. Over time, the source argues, confidence in the dataset will erode and organizations will be pushed to build alternative intelligence pipelines—adding cost, new tooling, operational complexity, and, predictably, increasing failure rates.

Action1’s proposed mitigation: correlated feeds and integrated remediation

Gene Moody, Field CTO at Action1, lays out a defensive model centered on correlation and workflow integration. Action1 combines multiple sources—VulnCheckNVD++, NIST NVD, CISA’s KEV Catalog, Microsoft’s MSRC data and vendor release notes—then scores each vulnerability using CVE data, CVSS severity, CISA KEV status and known usage in ransomware campaigns to provide an initial prioritization in minutes. That intelligence is correlated with real‑time endpoint data so teams can determine which vulnerabilities actually affect deployed software.

Crucially, Action1 positions remediation as part of the same workflow: once an affected endpoint is identified, the system is designed to move directly to remediation without requiring export, manual correlation, or a separate handoff. The idea, as described in the source, is to shorten the time between discovery, prioritization and patching so remediation keeps pace with accelerated discovery.

What this means for security teams, NIST and CISA, and vendors

  • Security teams and enterprise defenders: Expect to rely on multiple feeds and internal asset correlation rather than a single authoritative NVD baseline; be prepared to invest in mature tooling and processes that turn fragmented intelligence into binary decisions—does this affect us, how urgent is it, and can we patch now?
  • NIST and CISA: Operational choices that prioritize recent CVEs will reduce immediate processing burden but create a persistent backlog that demands transparency about processing priorities and timelines; the KEV Catalog and other curated lists will remain important complementary inputs.
  • Vendors and researchers: With standardized enrichment lagging for some CVEs, vendor advisories, release notes and independent research will be even more central to defensive decision‑making and to the public record attackers can exploit.

The shift described in the source is straightforward: discovery is accelerating faster than the older tooling and processes were designed to handle. The practical test for defenders, according to the author and the Action1 report, will be whether prioritization, correlation and integrated remediation can shorten the interval from “we know a vulnerability exists” to “we have reduced exposure.” If discovery keeps outpacing enrichment, the NVD remains critical—but no longer sufficient on its own.

https://www.bleepingcomputer.com/news/security/ai-is-accelerating-vulnerability-discovery-can-defenders-keep-up/