Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

The National Institute of Standards and Technology (NIST) is grappling with a daunting challenge: how to manage the ever-growing deluge of software vulnerabilities. The problem has been exacerbated by AI-augmented research and scanning, which has led to a surge in vulnerability discovery. To address this issue, NIST is seeking guidance on whether AI can be used not only to discover flaws but also to prioritize and remediate them.

The sheer volume of new vulnerabilities is overwhelming cybersecurity professionals. According to data from CVE.ICU, there have been over 50,000 reported software vulnerabilities so far in 2026, a 72% increase compared to last year. And experts predict that this number will continue to rise, potentially by as much as 50% or more by the end of the year.

However, not all vulnerabilities are created equal. In fact, most issues are unlikely to be exploitable. According to an analysis by Jerry Gamblin, a principal engineer at Cisco and the creator of CVE.ICU, less than 1% of reported vulnerabilities from two major sources – GitHub and VulnCheck – have been deemed exploitable. This raises the question: does the sheer volume of vulnerabilities matter for defenders?

The real challenge facing NIST is not just about managing the volume but also about communicating the critical issues effectively to cybersecurity professionals. Historically, the National Vulnerability Database (NVD) has provided descriptive data on software flaws, but it often lacks context. For example, while the database can indicate the severity of a vulnerability, it may not provide information on whether it’s being actively exploited or offer guidance on remediation.

To address this gap, NIST is seeking input from stakeholders on how to modernize the NVD and incorporate AI into its operations. Specifically, the agency wants to know how AI and other automated mechanisms can be used to improve contextual risk prioritization and whether AI systems have a role in automated vulnerability remediation. By leveraging AI, NIST hopes to provide more prescriptive guidance that will help defenders prioritize their efforts and focus on the most critical issues.

While there is no easy solution to this complex problem, one thing is clear: modernizing the NVD is essential to keeping pace with the rapidly evolving cybersecurity landscape. As Karthik Swarnam, chief security and trust officer at ArmorCode, notes, “The deeper question is whether this volume surge matters for defenders.” By providing more context and actionable guidance, NIST can help defenders make informed decisions about which vulnerabilities to prioritize and how to remediate them effectively.

For cybersecurity professionals, the practical takeaway from this development is clear: stay vigilant and keep a close eye on the evolving threat landscape. With the right tools and information, you can navigate even the most daunting vulnerability management challenges.


Source: Dark Reading — 2026-08-14