‘The economics of vulnerability discovery have changed’: NIST wants to modernize the National Vulnerability Database amid AI advances – cyber experts say it needs to be redesigned with machine-speed in mind
The National Vulnerability Database was designed for human-speed. Advances in AI mean it needs a much-needed overhaul
NIST has issued a call for advice on how it can modernize the National Vulnerability Database (NVD) in light of recent AI advances – cyber experts have told ITPro that it’s desperately needed.
In a recent request for information (RFI), the institute said it is seeking stakeholder input on how to overhaul the vulnerability reporting service. The NVD plays a key role in helping organizations keep their finger on the pulse of the threat landscape.
The database acts as a catalog for software and hardware-related security flaws, drawing on the Common Vulnerabilities and Exposures (CVE) system to provide details and guidance on vulnerabilities.
Yet recent AI advances, particularly in the cybersecurity field, have raised the stakes when it comes to vulnerability identification and remediation.
Rob O’Connor, EMEA CISO at Insight, told ITPro that “the economics of vulnerability discovery have changed” due to AI. Humans simply can’t match the speed of agents, and that creates blind spots for security teams.
“Automated agents can analyse and triage code at a scale humans can no longer match,” he said. “This means the bottleneck now isn’t finding the vulnerabilities. Instead, it’s in contextualising and remediating them.”
Researchers at Forescout told ITPro earlier this year that businesses should prepare for an explosion of vulnerabilities, with AI now being used to identify software flaws at record pace.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Some big tech companies have already taken action on this front, including Apple. In late June, the company revealed plans to speed up software patching in direct response to AI.
At the core of NIST’s request, the institute said the goal is to “improve the NVD’s scalability, automation, interoperability, transparency, and utility”.
Put simply, AI is speeding things up, and the NVD needs to match the pace of vulnerability disclosures, which the institute itself recently admitted has become untenable.
In April, NIST revealed it would scrap efforts to analyze every submitted CVE, instead focusing on only the most severe vulnerabilities. The shake-up means that only CVEs that meet certain criteria will be ‘enriched’ with additional details and guidance.
The NVD was built around human speed
A key issue with the NVD in its current state is that it was designed around “human speed”, according to Crystal Morin, senior cybersecurity strategist at Sysdig.
The database launched in 2005, having evolved from an earlier setup known as the Internet-Categorization of Attacks Toolkit (ICAT). The scale – and indeed, speed – of threats at that time pales in comparison to what organizations face in 2026.
That’s not to suggest that reporting standards are obsolete, though - they just need a rethink to remain fit-for-purpose in an AI-powered era.
“They were designed for human speed. We now operate in a machine-speed world. A CVE with a static severity score tells you a flaw exists and, roughly, how bad it could be in theory. It doesn’t tell you whether it is exploitable in your environment, or if it’s already being weaponized,” she told ITPro.
With AI in the mix, Morin said this creates two distinct gaps: namely speed and the detail required to act on potential vulnerabilities.
“The reporting and enrichment pipeline still moves in weeks while exploitation moves in hours,” she said. “Second, the same detailed advisory that helps defenders is also raw material for AI-generated exploit code.”
“Ultimately, severity scoring on its own drives the ‘patch everything’ behavior that simply does not scale.”
Morin noted that Sysdig’s threat intelligence unit saw this dynamic play out in real-time when a Langflow vulnerability with a 9.9 CVSS score “essentially sat untouched while a lower-scored 9.3 vulnerability in the same product was mass exploited”.
“Standards must evolve toward data that is real-time, machine-readable, and grounded in real-world exploitability rather than theoretical severity.”
Designing for machine consumption
Efforts to modernize the NVD should focus primarily on designing it for “machine consumption”, according to Rob O’Connor, EMEA CISO at Insight.
With AI playing an increasing role in vulnerability management, curating easily consumed information could help speed up reaction times for security practitioners.
“I’d recommend designing it primarily for machine consumption, with human users as a secondary consideration,” he told ITPro. “As vulnerability management becomes more automated, data needs to be structured so machines can interpret and act on it easily, while remaining clear and useful for human analysts.”
Douglas McKee, director of vulnerability intelligence at Rapid7, noted that the ecosystem has already begun moving toward “structured enrichment” through authorized data publishers (ADPs).
These are organizations that are authorized to “enrich the content” of CVE records, a practice that NIST noted earlier this year that it will roll back.
Elsewhere, standards such as the Common Security Advisory Framework (CSAF) and the Vulnerability Exploitability eXchange (VEX) also provide machine-readable information on what specific products are affected by flaws.
“Those are exactly the kind of building blocks an automated vulnerability management system needs,” McKee told ITPro.
“I would move the NVD toward a federated enrichment model rather than trying to make NIST the place where every piece of vulnerability analysis has to happen. Let CNAs, vendors, researchers, and qualified data publishers contribute structured enrichment while the NVD acts as the trusted aggregation and normalization layer.”
Morin echoed McKee and O’Connor’s comments regarding machine-speed upgrades to the database.
“My core recommendation would be to evolve the NVD from telling defenders a vulnerability exists to telling them the extent to which it matters in production environments, in real time and in a form machine-speed security can act on,” she said.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Why resale alone can no longer carry the channelIndustry Insights Resale alone no longer sustains partner growth in today's software market
-
Off-grid: networks cut the cordOpinion Faster, more robust wireless connections offer alternatives to the LAN and public hotspots. But how do IT leaders navigate their way through 5G, 6G, and satellite technology?
-
OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'News The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
-
Researchers warn millions of RDP and VNC servers are wide open to exploitationNews Researchers at Forescout spotted millions of RDP and VNC servers exposed online
-
NIST is overhauling the National Vulnerability Database due to skyrocketing reports – experts worry it will ‘leave many CVEs on the table’News Drowning in CVEs, the NIST agency will now fully analyze only the most severe vulnerabilities
-
Brace yourselves for a vulnerability explosion, Forescout warnsNews AI advances are helping identify software flaws at record pace and scale, but that's not the good news some would think
-
Ubuntu vulnerability exposes enterprises to root escalation, complete system compromiseNews The high-severity Ubuntu vulnerability allows an unprivileged local attacker to escalate privileges through the interaction of two standard system components
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023