NIST seeks NVD overhaul as AI outpaces vulnerability management
The RFI marks the first federal admission that periodic scanning and manual triage can't keep up with AI-driven threat discovery, and the first structural push to replace them.
TL;DR
NIST published an RFI seeking input on restructuring the National Vulnerability Database to handle AI-accelerated vulnerability discovery and near-real-time threat enrichment. The RFI directly states that "traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly inadequate." Organizations relying on NVD for prioritization and remediation would face a fundamentally altered information flow under continuous, automated enrichment. It's the first federal admission that the old model is structurally obsolete.
NIST's request for information, set to publish Wednesday in the Federal Register, puts the problem plainly: "The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent." The agency is asking the public how to restructure the National Vulnerability Database for an environment where large language models can find and exploit vulnerabilities at scale, and where defenders need "near real-time vulnerability enrichment" rather than batched updates.
The admission is overdue. NIST has spent the past two years losing ground to the vulnerability flood. In April 2026, the agency narrowed its enrichment criteria to only CVEs in CISA's Known Exploited Vulnerabilities catalog and software meeting federal or EO 14028 criticality thresholds, effectively abandoning comprehensive analysis for everything else (nist.gov, Apr. 15, 2026). A Commerce Department IG report in May 2026 documented the results: an enrichment backlog exceeding 27,000 CVEs and severity scores that matched independent evaluators only 12% of the time. Analysts were spending 80% of their time on scoring and product identification that vendors had often already performed (cyberscoop.com, May 29, 2026). The database's enrichment contract had lapsed in February 2024, and the backlog only grew.
The RFI asks pointed questions about automation: how defenders should integrate AI into vulnerability enrichment, and what transparency and auditability look like when decisions are machine-made. It also raises the question of automated remediation. NIST's framing, "continuous, contextual, and automated," signals that the agency envisions a database that enriches and distributes vulnerability data in something closer to real time than the current batch model.
What isn't answered is how this overhaul interacts with Treasury's "Gold Eagle" AI threat-sharing clearinghouse, rolled out last month, or with the White House's VINCE platform at Carnegie Mellon's SEI, which collects AI-discovered vulnerability reports. The RFI doesn't define the division of labor, and it gives no timeline for the restructuring. For the organizations whose vulnerability programs are built around NVD data feeds, the operational question is simpler: when does the pipeline change, and what do they need to re-engineer to receive it? NIST isn't saying yet.
Published ·Deep Fathom