The US National Institute of Standards and Technology (NIST) is prepping further changes to its vulnerability database in response to the AI-powered increase in vulnerabilities.
The government-backed organisation is taking the issue to the private sector, publishing a request for information on how it should tackle the growth and complexity of vulnerabilities and demand for “near real-time” enrichment.
The RFI said: “The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent… The advancement of AI presents an opportunity to transform the vulnerability management ecosystem.”
It comes a few months after NIST said it would no longer enrich all CVEs submitted to the NVD in April 2026, after seeing a 264% increase in submissions between 2020 and 2025.
Its enrichment process involves adding reference tags, a common weakness enumeration identifier (CWE), and flagging software that is particularly vulnerable to the vulnerability.
A backlog
Get the full story: Subscribe for free #
Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.
[Subscribe now](https://www.thestack.technology/membership/)
Already a member? [Sign in](https://www.thestack.technology/signin/)