NVD gaps push security teams to AI triage

The gist
AI-fueled cyberattacks are accelerating faster than defenders can patch, just as the National Vulnerability Database slashes its coverage—leaving organizations scrambling for smarter, machine-speed defenses.
What to know
- In 2026, the NVD began analyzing only high-risk CVEs, leaving 38% of vulnerabilities uncovered and pushing security teams to rely on AI-powered platforms like Snyk for threat intelligence.
- AI-enabled attacks exploded by 89% in 2025, with IBM reporting exploits now happening in under 30 seconds—obliterating the old 30-day patch cycle.
- With patch delays averaging 69 days and attackers still three months ahead, organizations must blend AI automation with deep internal risk context to avoid falling behind.
AI Redefines the Attack Window
AI-driven discovery and exploitation have collapsed the gap between vulnerability exposure and attack to minutes, overwhelming human-centric security models and forcing organizations to operate at machine speed or risk multi-actor breaches.
The advent of AI-driven vulnerability discovery has compressed the window between flaw identification and exploitation from weeks to mere hours, drastically intensifying the operational pressure on security teams. According to CrowdStrike's 2026 Global Threat Report, AI-enabled adversaries increased their operations by 89% year-over-year in 2025, with IBM reporting average breakout times as low as 29 minutes, and some exploits occurring in under 30 seconds. Despite this alarming acceleration, many organizations remain sluggish in patching vulnerabilities, often unaware that the traditional 30-day remediation cycle is now dangerously obsolete, leaving systems exposed to rapid, multi-actor attacks—as seen when a single compromised machine hosted 70 different threat actors within a month of vulnerability disclosure.
AI's relentless surge in vulnerability detection has overwhelmed traditional triage and remediation workflows, with Mozilla's agentic AI pipeline uncovering 12 times more bugs than previous methods, including flaws dormant for over 15 years. This explosion in volume—FIRST raised the 2026 CVE forecast to 66,000, 46% above earlier projections—has doubled patching workloads, yet the proportion of actively exploited vulnerabilities remains steady, underscoring the critical need for smarter prioritization. Adobe exemplifies this strategic pivot by embedding AI across detection, testing, and even AI-assisted pull request creation, acknowledging that if adversaries harness AI, defenders must do the same to sift actionable signals from the noise and accelerate response.
The AI-driven arms race has fundamentally outpaced human-centric security models, as highlighted by Inteza CEO Itay Tevet, who warns that the assumption of infinite human analyst capacity is 'completely broken' amid surging AI-generated alerts and attacks. This relentless escalation forces organizations to rethink security workflows to operate at machine speed, abandoning outdated quarterly or annual validation cycles in favor of real-time, adaptive strategies. The offensive-defensive gap remains stubbornly wide—estimated at a three-month lead for attackers—compounded by the democratization of sophisticated AI-powered cyber tools beyond nation-states, which multiplies both the volume and sophistication of threats.
To survive this new reality, organizations must adopt dynamic triage frameworks leveraging tools like EPSS and the CISA KEV catalog to focus scarce resources on exploited vulnerabilities, while doubling patch-verification staffing to address the human bottleneck. The proliferation of AI-generated throwaway applications containing untracked flaws further complicates inventories, demanding innovative approaches such as AI-generated bills of materials beyond traditional CVE systems. Some are turning to outsourced, automated patching solutions—akin to consumer software updates—as Adobe and vendors like Echo advocate, signaling a strategic shift toward seamless, AI-augmented vulnerability management that can keep pace with machine-speed adversaries.
NVD Coverage Crisis Unfolds
With the NVD now leaving nearly 40% of vulnerabilities unanalyzed and public severity scores increasingly unreliable, security teams must blend multi-source AI intelligence and human validation to fill critical threat intelligence gaps.
By early 2026, the National Vulnerability Database (NVD) has dramatically shifted its approach, prioritizing only high-risk CVEs due to an unsustainable volume of submissions. As announced by NIST on April 15, 2026, full enrichment of every CVE is no longer feasible, focusing instead on vulnerabilities listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog and other critical criteria. This strategic pivot leaves approximately 38% of published CVEs without scheduled analysis, with only about 20% receiving a NIST CVSS vector, creating significant coverage gaps and undermining the NVD’s reliability as a comprehensive vulnerability source.
The erosion of NVD’s enrichment coverage and declining accuracy—highlighted by discrepancies such as a vulnerability scored 9.1 Critical by NIST but assessed independently at 4.4 Medium—has compelled organizations to rethink their vulnerability management strategies. Companies like Snyk have responded by integrating multi-source, AI-assisted intelligence platforms that combine diverse vulnerability feeds, security analyst validation, and open source context. This hybrid approach, blending AI-driven workflows with human-in-the-loop validation, enables more comprehensive and timely analysis, effectively supplementing or replacing traditional NVD enrichment.
With the NVD no longer serving as a single source of truth, organizations face the complex challenge of applying unique internal context—such as asset criticality and data sensitivity—into customized risk scoring frameworks. As PlexTrac’s founder Dan DeCloss emphasizes, cybersecurity teams can no longer rely on public severity claims in CVE submissions, which have become increasingly unreliable without NVD enrichment. Instead, they must own deeper internal analysis and risk validation, leveraging AI-assisted multi-source intelligence combined with tailored business context to prioritize and remediate vulnerabilities effectively amid the growing volume and complexity.
Prioritization Demands Deep Context
Generic CVE lists are obsolete—effective risk management now requires integrating asset criticality, system exposure, and business context for tailored, continuous vulnerability prioritization and remediation.
As the National Vulnerability Database (NVD) scales back enrichment to only high-risk CVEs, organizations like PlexTrac emphasize the urgent need to embed deep internal context into vulnerability prioritization. Dan DeCloss highlights that relying solely on public CVE data is no longer viable; instead, businesses must integrate unique factors such as asset criticality, system exposure, and data sensitivity to accurately assess risk. This shift demands continuous reprioritization informed by evolving threat intelligence and compensating controls, especially as the window between vulnerability disclosure and exploitation rapidly shrinks, requiring swift mitigation strategies before full remediation can occur.
Despite the clear necessity for contextualized risk assessments, operational challenges persist due to the sheer volume of vulnerabilities and the lack of streamlined mechanisms for applying customized risk scoring uniformly across enterprises. Dan DeCloss points out that without easy integration of unique business context into automated workflows, teams struggle to move beyond generic CVE lists to a nuanced understanding of exposures and attacker behaviors. Moreover, while automation—bolstered by AI tools like large language models—is increasingly employed to handle routine tasks such as reporting and tracking, it cannot replace human judgment in validating risk and orchestrating true remediation without rich internal context.
To combat alert fatigue and prevent vulnerabilities from becoming an unmanageable technical debt, organizations must establish foundational vulnerability management programs with dedicated ownership and ongoing hygiene efforts. This includes maintaining accurate asset inventories, clarifying system ownership, and embedding security hygiene practices such as identity management, third-party inventory (now expanded to include AI tools), secrets governance, and certificate lifecycle management. As emphasized in 2026 security investment priorities, treating these hygiene tasks as continuous program work rather than ad hoc projects is critical to sustaining effective prioritization and remediation amid the evolving threat landscape.
Trust and Collaboration Under Siege
Attackers targeting trusted infrastructure and exploiting collaboration gaps force organizations to embed trust, governance, and real-time intelligence sharing at the core of their defense strategies.
The evolving cybersecurity landscape underscores trust as the foundational challenge, with attackers exploiting not just technical vulnerabilities but the very reliance on critical infrastructure ill-equipped for sustained adversarial pressure. As highlighted in the analysis of nation-state campaigns like China’s UNC6508, adversaries increasingly prioritize long-term intelligence collection targeting sectors such as medical research and AI development, compelling organizations to embed trust considerations deeply within their vulnerability management strategies.
Strategic defense-in-depth has become imperative as attackers focus on highly trusted network edge devices and AI infrastructure—prime gateways into enterprise environments. Companies like Palo Alto with GlobalProtect and Cisco with SD-WAN continue to face active exploitation, illustrating the urgency for operational discipline that extends beyond patching to include governance, credential hygiene, and trust validation. This shift is critical as AI technologies rapidly expand the attack surface faster than security teams can secure them, necessitating internal contextual analysis to prioritize vulnerabilities effectively.
Collaboration emerges as a vital but challenging pillar in modern vulnerability management, with the WannaCry incident serving as a turning point demonstrating the power of real-time intelligence sharing. Yet, as Michael Daniel notes, cultural and legal barriers persist despite technical standards like structured threat intelligence exchange. Sustaining scalable collaboration demands not only trust-building but also robust technical infrastructure and honest peer communication, which are essential for navigating the AI-accelerated threat landscape and shrinking public enrichment resources.
The offense-defense dynamic remains skewed, with offensive cyber capabilities maintaining a lead of approximately three months over defensive tools, as observed in conflicts like Russia-Ukraine. Financial institutions, particularly major banks, stand out as models due to their relatively advanced cybersecurity investments, offering a blueprint for other sectors. However, persistent governance and execution gaps—such as delayed patching averaging 69 days and neglected credential management—exacerbate exposure, underscoring that robust operational discipline and surface reduction strategies are now survival imperatives in an era where attackers leverage AI to accelerate and scale attacks.





