The U.S. National Institute for Standards and Technology (NIST) is on a mission to modernize its National Vulnerability Database (NVD). This initiative aims to tackle the evolving challenges of cybersecurity, especially those posed by artificial intelligence (AI). By embracing automation and AI-driven workflows, NIST seeks to transform how vulnerabilities are managed and reported.
On August 12, NIST published a request for information (RFI) in the Federal Register, calling on stakeholders to provide their insights about the modernization of the NVD. The request emphasizes the need for feedback on opportunities, challenges, and essential priorities to enhance the NVD within an increasingly complex cybersecurity environment shaped by AI technologies. This initiative is particularly timely, given the rapid advancements in AI that continue to influence how organizations approach security.
NIST is actively seeking “forward-looking perspectives, practical recommendations, and innovative models” aimed at improving various facets of the NVD. These facets include scalability, automation, interoperability, transparency, and overall utility. The aim is to create a database that not only adapts to modern challenges but also serves as a dependable resource for cybersecurity experts and organizations alike.
Currently, the NVD functions by automatically ingesting common vulnerabilities and exposures (CVE) records, usually within an hour. Following this automated intake, analysts curate the data by adding crucial information, such as severity ratings and versions of affected products. This enriched information is made accessible via the NVD website and a set of automated tools. However, NIST has recognized that traditional vulnerability management techniques—often reliant on periodic scanning, static prioritization, and manual remediation—are fast becoming insufficient in today’s fast-paced technological landscape.
The RFI underscores the fact that vulnerability management is in a state of flux due to several factors, including AI-enabled tools, more rapid technology cycles, an increase in the volume of vulnerabilities, and a growing demand for both automation and near-real-time data. NIST has identified AI not only as a critical tool for modernization but also as a double-edged sword, presenting risks such as AI-assisted vulnerability discovery and the potential for exploitation.
The organization is eager to gather input from the community to construct a system that is “continuous, contextual, and automated.” Such a system would be designed to respond efficiently to emerging threats, aligning with the priorities of various organizations. The RFI includes a comprehensive list of 30 questions aimed at soliciting feedback on what changes stakeholders believe are necessary for the NVD and how best to integrate AI and automation workflows into its operations.
Tyler Reguly, who serves as the associate director of security research and development at Fortra, has emphasized the potential benefits of utilizing AI in the discovery of vulnerabilities, particularly when examining source code. He noted that AI can uncover “all sorts of obscure vulnerabilities” that might escape the attention of human researchers. However, Reguly also cautioned against placing too much trust in AI when it comes to remediation, especially within critical or production-level systems.
He articulated, “I would not trust the remediation of vulnerabilities in critical systems to AI just yet,” underscoring that the concept of a “human-in-the-loop” remains essential in the current landscape of cybersecurity. Reguly acknowledged that while AI-driven remediation may have its place in test environments and laboratories, it is not yet suitable for use in production systems, where the stakes can be significantly higher.
Stakeholders interested in contributing to this pivotal modernization effort have until October 13 to submit their insights and recommendations. The outcome of this initiative could set the stage for a new standard in vulnerability management, ultimately enhancing organizational resilience in the face of an ever-evolving threat landscape. By fostering collaboration and tapping into a wide range of experiences and insights, NIST aims to ensure the National Vulnerability Database remains an invaluable resource for cybersecurity professionals in a world increasingly shaped by artificial intelligence.

