Protect.Computer
NEWS

NIST Seeks AI Help to Manage Exploding Vulnerability Database

· 1 min read
NIST Seeks AI Help to Manage Exploding Vulnerability Database

Eight months into 2026, the number of reported software vulnerabilities has hit 50,340 — a 72% jump over the same point in 2025. The surge is straining the National Institute of Standards and Technology’s ability to keep its National Vulnerability Database (NVD) current. NIST has now issued a formal Request for Information asking researchers, software vendors, and other stakeholders how artificial intelligence should be used to redesign the NVD, with a focus on scalability, automation, interoperability, and making the data more useful in machine-readable form.

The urgency is real. The window between a vulnerability being publicly disclosed and being actively exploited in the wild has collapsed from roughly 70 days in 2020 to under a single day in 2026 — with the shortest observed window now measured in hours. Staff cuts at NIST over the past 18 months have made keeping pace with even a normal CVE load difficult; the AI-driven spike in automated vulnerability discovery has widened the gap further. The RFI is NIST’s attempt to crowdsource a blueprint for an NVD that can keep up with the pace of modern software security — and eventually help defenders triage what matters before attackers get there first.

Sources

Related reading