The National Institute of Standards and Technology (NIST), a US Commerce Department standards agency, is asking which parts of vulnerability management can be automated with AI and which should remain under human review as it considers how to modernize the National Vulnerability Database.

The request for information (RFI) on the National Vulnerability Database (NVD) is open until Oct. 13 at midday Eastern Time.

NIST is also seeking input on AI-assisted prioritization, auditability, integration with vendor advisories, threat intelligence and asset-management systems, and safeguards for AI-generated remediation.

The NVD ingests Common Vulnerabilities and Exposures (CVE) records within about an hour of publication, after which analysts may add information such as severity scores and affected product versions.

Surging submissions and a growing backlog

Record growth has already changed where NIST spends analyst time. The agency said CVE submissions rose 263% from 2020 to 2025 and were nearly one-third higher in the first three months of 2026 than a year earlier. In April, NIST began prioritizing enrichment for the Known Exploited Vulnerabilities Catalog maintained by the Cybersecurity and Infrastructure Security Agency (CISA), software used by the federal government and critical software. Other CVEs remain listed but are not scheduled for immediate enrichment.

A May Commerce Department inspector general review found the backlog grew from about 13,000 vulnerabilities at the start of June 2024 to more than 27,000 by the end of 2025. It projected that more than 60,000 vulnerabilities would be reported in 2026 and said NIST would be unable to clear the backlog or prevent future processing delays without significant changes. NIST concurred with the evaluation’s six recommendations and said it was working to implement them.

Manual bottlenecks and recent adjustments

Severity scoring and assigning product applicability statements consumed an estimated 80% of enrichment processing time, the evaluation found. Common Platform Enumeration applicability statements identify affected versions and configurations in machine-readable form, but creating them remained manual and time-consuming.

NIST has also reduced some duplicated analysis and expanded structured data available through the NVD. Since April, it has stopped routinely producing a separate severity score when a CVE Numbering Authority has already provided one. In June, the NVD added CISA’s Stakeholder-Specific Vulnerability Categorization data and “affected” product information to feeds and APIs alongside existing Common Vulnerability Scoring System scores.

Industry calls for operational context

Karthik Swarnam, chief security and trust officer at ArmorCode, an application security software company, argued for more operational context. “A technically severe vulnerability is not necessarily an operationally urgent vulnerability. Conversely, a lower-severity vulnerability that is internet-facing and being actively exploited may represent significantly greater immediate risk,” he said in comments about the RFI shared with TechInformed.

Swarnam also called for remediation information, including whether a fix exists, which versions contain it and the provenance of that information. “A CVE should not be viewed as a static record. Its technical characteristics may not change, but its operational risk can change substantially over time,” he said.

Shaping the future of vulnerability management

The RFI asks what data organizations need to prioritize vulnerabilities in production, how NVD data should connect with remediation workflows and what controls should govern AI-generated fixes. It does not commit NIST to a specific AI architecture or identify which tasks will be automated. NIST said responses will inform future planning, technical architecture, standards and data governance; the notice sets no implementation date.

Personalized Feed
Personalized Feed