Published Security3 min read
NIST concedes manual NVD enrichment no longer scales, and gives 62 days to argue about the fix
A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- NIST published a request for information on modernizing the National Vulnerability Database in the Federal Register on August 12.
- NIST said it sought stakeholder input on opportunities, challenges and priorities for modernizing the NVD in "an evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data."
- The RFI states: "The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent."
- Today the NVD automatically ingests CVE records within about an hour, after which analysts add information such as severity scores and affected product versions; the enriched records are available through the NVD website and automated tools.
- NIST said the NVD has seen increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, increased reliance on automation and machine-readable security data, and demand for near real-time vulnerability enrichment from defenders facing faster threats.
Compiled by The WatchSomething wrong?How this is made
Why it matters
NIST published a request for information in the Federal Register on August 12 asking how it should modernize the National Vulnerability Database for what it calls a cybersecurity landscape "increasingly shaped by AI and machine-consumable security data" [1][2]. Buried in the framing is an admission with operational consequences: the agency states that "the inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent" [3].
That sentence describes how most vulnerability management programs actually run. It also describes the NVD itself. Today the database ingests CVE records automatically within about an hour, after which human analysts attach severity scores and affected product versions, and the enriched records are served to the website and to automated tools [4]. The enrichment step is the part that carries the weight for downstream tooling, and it is the part staffed by people.
NIST lists the pressures it is responding to: rising volume and complexity of disclosed vulnerabilities, inconsistent data quality, growing reliance on automation and machine-readable security data, and demand from defenders for near real-time enrichment [5][6]. It also frames AI as both cause and possible cure, citing AI-assisted vulnerability discovery and exploitation as a risk while presenting automation as the route to a system that is "continuous, contextual, and automated" [7][8]. According to CyberScoop, NIST is specifically concerned that large language models are becoming more capable of finding and exploiting vulnerabilities at scale [9].
The RFI carries 30 questions and closes on October 13, which is 62 days of comment window [10][11][12]. The questions are not abstract. NIST asks how automation can be built into the reporting process, which capabilities, products and processes would get information to stakeholders faster, how to build transparency and auditability into AI-driven decisionmaking, and what role AI should play in automated remediation [13]. Anyone whose scanner, SBOM tooling or ticket queue depends on NVD field semantics has a direct interest in the answers to the second and third of those.
There is a practitioner counterweight worth reading into the record. Tyler Reguly, associate director of security R&D at Fortra, told Infosecurity Magazine that AI is useful for discovery, particularly against source code, where it can surface "all sorts of obscure vulnerabilities" human researchers miss [14]. On the remediation side he was blunt: "I would not trust the remediation of vulnerabilities in critical systems to AI just yet," adding that "human-in-the-loop is still so critical" and that lab and test environments are a different matter from production [15][16].
The NVD is also no longer the only federal venue for this data. A month before the RFI, the Trump administration launched Gold Eagle, a Treasury-overseen clearinghouse for sharing AI threat information between government and industry [17], and the White House partnered with Carnegie Mellon's Software Engineering Institute on the Vulnerability Information and Coordination Environment, VINCE, to collect and distribute reports on AI-discovered vulnerabilities [18]. How Treasury's process will interact with the NVD is not clear [19].
Watch what NIST does after October 13, because the RFI itself says a larger strategy comes only after these questions are answered [20]. Watch whether the responses argue for keeping analyst enrichment as a guaranteed field or treating it as best effort, and watch whether auditability of AI-generated enrichment becomes a stated requirement or a stated aspiration. Programs that treat NVD severity and affected-version data as ground truth should assume those fields are now in scope for redefinition.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
NIST published a request for information on modernizing the National Vulnerability Database in the Federal Register on August 12.
ReportedView cited source - [2]
NIST said it sought stakeholder input on opportunities, challenges and priorities for modernizing the NVD in "an evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data."
ReportedView cited source - [3]
The RFI states: "The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent."
ReportedView cited source - [4]
Today the NVD automatically ingests CVE records within about an hour, after which analysts add information such as severity scores and affected product versions; the enriched records are available through the NVD website and automated tools.
ReportedView cited source - [5]
NIST said the NVD has seen increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, increased reliance on automation and machine-readable security data, and demand for near real-time vulnerability enrichment from defenders facing faster threats.
ReportedView cited source - [6]
The RFI highlighted that vulnerability management is changing rapidly due to AI-enabled tools, faster technology cycles, growing vulnerability volumes and increased demand for automation and near-real-time data.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comdjohnsonAug 11NIST wants to overhaul its vulnerability database for the AI age
- infosecurity-magazine.comAug 12NIST Seeks Public Input on AI-Ready NVD Modernization
Additional citations
- Tyler Reguly, Fortra, via Infosecurity Magazine



