As AI-powered vulnerability discovery tools accelerate the rate at which new vulnerabilities are identified, cybersecurity defenders are facing a daunting challenge: can they keep up with the sheer volume of threats? A recent update to the National Vulnerability Database (NVD) has introduced changes that prioritize newer vulnerabilities over older ones, but this shift comes with risks and unintended consequences.
The NVD is a critical resource for security teams worldwide, providing structured metadata and contextual information about known vulnerabilities. However, in April 2026, the National Institute of Standards and Technology (NIST) announced updates to NVD operations, which have led to roughly 30,000 previously published vulnerabilities being reclassified as “Not Scheduled.” This change aims to address the growing backlog of vulnerability disclosures, but it raises concerns about how older, unprocessed vulnerabilities will be handled.
The reality is that the volume of disclosed vulnerabilities has grown exponentially in recent years. Action1’s 2026 Software Vulnerability Ratings Report found that critical and high-severity vulnerabilities increased by 103% each in 2025 compared to 2024, while remote code execution vulnerabilities rose by a staggering 128%. This puts immense pressure on systems designed for slower vulnerability discovery rates, leading to an expected backlog.
The core issue is not the existence of a backlog itself but how it’s managed. By prioritizing newer vulnerabilities over older ones, the system implicitly deprioritizes vulnerabilities that may already be known and discussed by vendors or researchers but lack full NVD context. This creates an information asymmetry between attackers and defenders: while attackers can correlate vendor advisories, security research, and public disclosures without waiting for standardized enrichment, security teams relying on NVD may see incomplete or delayed data.
Enrichment is not a cosmetic process; it provides critical contextual information that helps defenders determine whether a vulnerability applies to their environment and how urgently it should be addressed. Without this information, organizations are often forced to wait for additional context or make decisions using fragmented information – neither outcome is ideal in today’s threat landscape where exploitation can move faster than internal validation and remediation processes.
Moreover, the rolling backlog created by selectively draining older entries while continuously feeding new ones introduces uncertainty about coverage. Without a clear commitment to processing older entries within a defined timeframe, the backlog becomes a semi-permanent condition. This complicates prioritization for practitioners, as incomplete or overly broad affected-product information can lead to false positives and erode confidence in the dataset.
As a result, organizations may be forced to build alternative intelligence pipelines, leading to additional cost, tooling, and operational complexity – along with increasing failure rates. Action1’s 2026 Software Vulnerability Ratings Report highlighted that enterprise application exploitation surged by 800% in the last year, underscoring the need for effective vulnerability management.
In conclusion, while AI-powered tools accelerate vulnerability discovery, cybersecurity defenders must adapt to a rapidly changing landscape. It is essential to address the underlying issues driving these changes and prioritize a more comprehensive approach to vulnerability management, one that balances the need for speed with the importance of accuracy and completeness.
Source: Bleeping Computer — 2026-08-28