A Database Under Pressure
The US National Institute of Standards and Technology (NIST) is asking the cybersecurity community to help it drag the National Vulnerability Database (NVD) into the age of artificial intelligence. On August 12, the agency published a request for information (RFI) in the Federal Register, inviting stakeholders to weigh in on how to modernize the NVD for what it calls “an evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data.”
The NVD is the backbone of vulnerability management for countless organizations. It automatically ingests Common Vulnerabilities and Exposures (CVE) records within about an hour, then analysts enrich each record with severity scores, affected product versions, and other context. That enriched data flows out through the NVD website and automated tools used by security teams worldwide.
But the system is straining. NIST says traditional methods — periodic scanning, static prioritization, manual remediation — no longer cut it. Vulnerability volumes are exploding, technology cycles are faster, and organizations want near-real-time data and deeper automation. The RFI lays out a vision for a system that is “continuous, contextual, and automated.”
This is not just a routine update. The NVD is a critical piece of national infrastructure, and how it evolves will shape vulnerability management for years to come.
Why AI Changes the Game
The RFI doesn’t treat AI as a passing trend. NIST sees it as both an opportunity and a threat.
On the upside, AI could help automate CVE enrichment, spot patterns in vulnerability data, and even assist in discovering new vulnerabilities. The agency wants to integrate AI tools and automation workflows directly into the NVD’s operations.
On the downside, AI is also enabling attackers. AI-assisted vulnerability discovery and exploitation are real concerns, and NIST acknowledges that the same technology that helps defenders can also help adversaries find and weaponize flaws faster.
The RFI includes 30 questions covering everything from scalability and interoperability to transparency and utility. NIST is looking for “forward-looking perspectives, practical recommendations and innovative models” — not just tweaks, but a fundamental rethinking of how the NVD should work.
What Experts Say About AI in Vulnerability Management
Tyler Reguly, associate director of security R&D at Fortra, sees real promise in using AI for vulnerability discovery. “AI can be beneficial when analyzing source code,” he says. “It can identify all sorts of obscure vulnerabilities that human researchers might overlook.”
But he draws a hard line at remediation. “I would not trust the remediation of vulnerabilities in critical systems to AI just yet,” Reguly warns. “Human-in-the-loop is still so critical.”
His advice: use AI in test environments and labs, but keep humans in charge of production systems. “In production systems… not yet.”
That’s a sentiment worth keeping in mind as NIST builds out its modernization plan. Automation can speed things up, but it shouldn’t replace human judgment where the stakes are highest.
Key Questions in the RFI
The RFI is not a vague call for comments. It’s a structured set of 30 questions designed to extract specific, actionable input. Here’s a snapshot of what NIST wants to know:
- How should the NVD prioritize vulnerability enrichment to keep pace with the growing CVE backlog?
- What AI tools and techniques could improve the accuracy and speed of CVE analysis?
- How can the NVD better support machine-consumable data formats for automated security tools?
- What transparency and accountability measures should be in place for AI-assisted analysis?
- How can the NVD balance automation with human oversight to maintain trust?
These aren’t just technical questions. They’re about governance, reliability, and the role of a national database in an era of AI-driven both defense and offense.
What’s at Stake
The NVD is more than a website. It’s the foundation for vulnerability scanners, patch management systems, and security research. If it can’t keep up with the pace of modern threats, the entire ecosystem suffers.
NIST’s move to modernize is overdue, but welcome. The agency is right to seek input early, before making major investments in AI and automation. The question is whether the final design will balance speed with accuracy, and automation with human judgment.
Stakeholders have until October 13 to submit their input. If you work in vulnerability management, this is a rare chance to shape the tools you’ll rely on for the next decade.
For more on how AI is reshaping security, check out our coverage of AI in vulnerability management and the broader shift toward automated threat intelligence. And if you’re still using manual CVE analysis, it might be time to start planning for the NVD’s AI-powered future.