By Tyler Reguly, Associate Director of Security R&D at Fortra
Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?
A more interesting question might be “has the National Vulnerability Database ever actually met the needs of defenders?” The only valuable information provided by NVD in the past has been CVSS information, and I’ll leave it up to the individual to decide if CVSS has ever been “valuable.” The other information provided by NVD was CPE data, and it has long been known that if you were using NVD CPE data for vulnerability detection, you were not getting accurate or reliable vulnerability detection.
What role should AI play in vulnerability discovery, prioritization, and remediation, and where is human oversight still necessary?
AI is playing a pretty strong role in vulnerability discovery with source code. That is the perfect application in my mind. We’re seeing the results with the size of the patch drops from companies like Microsoft and Oracle. When you let AI explore your source code, you fix all sorts of obscure vulnerabilities.
At the same time, we’re climbing a hill right now, discovering all the obscure issues that were either too buried, too complex, or too restrictive to be sought out by human researchers. Once these issues are all discovered and AI tools are run on new code bases, problems will be fixed before they are shipped, and those aren’t vulnerabilities and don’t require CVEs, so we’ll start to go back down the hill, and everything will normalize once again.
When it comes to prioritization, anything I’ve seen out of AI so far has been “good enough.” I’d call it on par with a junior analyst. I haven’t seen it perform prioritization as well as a VM expert.
Finally, remediation… I would not trust the remediation of vulnerabilities in critical systems to AI just yet. There’s no coming back from that. There’s a reason human-in-the-loop is still so critical, and as soon as AI starts remediating vulnerabilities, you lose the human oversight. In test environments, sure. In labs, definitely. In production systems… not yet.
What risks could organizations face if they rely too heavily on AI-generated vulnerability analysis and prioritization?
The risk is overlooking real risk. AI prioritization tends to rely on knowns and treats prioritization like a science. CVSS was used for years as a prioritization metric (they finally updated their documentation to advise against this, but people still use it that way). Prioritization is still, in my mind, an art. There’s a gut feeling that goes along with all the variables. You can get close (and some companies have interesting algorithms in the space), but you still have the art of it all that plays a major role in my mind.
How should security teams adapt their vulnerability management programs as attackers increasingly use AI to identify and exploit vulnerabilities faster?
Remember that vulnerability management is just one of the pillars of good cybersecurity hygiene. If you are layering it with FIM, EDR, and proper system hardening, then you’ve got a solid foundation. Yes, you have to make adjustments in some places, but remember that patches fix multiple vulnerabilities, that few vulnerabilities are ever actually exploited, and that known active exploitation increases risk. From there, a few simple choices will keep your VM program running smoothly.
If NIST successfully modernizes the NVD, what capabilities or improvements would have the biggest impact on organizations over the next five years?
First, we should talk about what modernization looks like. It’s better application of CPEs and CWEs. It’s inclusion of EPSS data alongside CVSS data. It’s providing better remediation guidance and a more structured list of external resources. My biggest fear is that OVAL will be seen as a useful standard and further adopted or that CPE data will continue to be less than complete. I’m not saying that everything needs better enrichment, but critical vulnerabilities need to be completely enriched and pulled out and better accessed. We need to deprioritize CVSS data. If we can start to make changes and improvements, then we may see a place where organizations can actually start to look for guidance. Right now, I would say that CISA Kev and CVE.org are a better combination of data than NVD, and I’m not sure anyone really needs to go to NVD. 10 years ago, NVD was at the top of the pecking order, and it would be interesting to see them return to that status.
Related
This entry was posted on August 12, 2026 at 8:00 am and is filed under Commentary with tags Fortra. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Guest Post: By Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?
By Tyler Reguly, Associate Director of Security R&D at Fortra
Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?
A more interesting question might be “has the National Vulnerability Database ever actually met the needs of defenders?” The only valuable information provided by NVD in the past has been CVSS information, and I’ll leave it up to the individual to decide if CVSS has ever been “valuable.” The other information provided by NVD was CPE data, and it has long been known that if you were using NVD CPE data for vulnerability detection, you were not getting accurate or reliable vulnerability detection.
What role should AI play in vulnerability discovery, prioritization, and remediation, and where is human oversight still necessary?
AI is playing a pretty strong role in vulnerability discovery with source code. That is the perfect application in my mind. We’re seeing the results with the size of the patch drops from companies like Microsoft and Oracle. When you let AI explore your source code, you fix all sorts of obscure vulnerabilities.
At the same time, we’re climbing a hill right now, discovering all the obscure issues that were either too buried, too complex, or too restrictive to be sought out by human researchers. Once these issues are all discovered and AI tools are run on new code bases, problems will be fixed before they are shipped, and those aren’t vulnerabilities and don’t require CVEs, so we’ll start to go back down the hill, and everything will normalize once again.
When it comes to prioritization, anything I’ve seen out of AI so far has been “good enough.” I’d call it on par with a junior analyst. I haven’t seen it perform prioritization as well as a VM expert.
Finally, remediation… I would not trust the remediation of vulnerabilities in critical systems to AI just yet. There’s no coming back from that. There’s a reason human-in-the-loop is still so critical, and as soon as AI starts remediating vulnerabilities, you lose the human oversight. In test environments, sure. In labs, definitely. In production systems… not yet.
What risks could organizations face if they rely too heavily on AI-generated vulnerability analysis and prioritization?
The risk is overlooking real risk. AI prioritization tends to rely on knowns and treats prioritization like a science. CVSS was used for years as a prioritization metric (they finally updated their documentation to advise against this, but people still use it that way). Prioritization is still, in my mind, an art. There’s a gut feeling that goes along with all the variables. You can get close (and some companies have interesting algorithms in the space), but you still have the art of it all that plays a major role in my mind.
How should security teams adapt their vulnerability management programs as attackers increasingly use AI to identify and exploit vulnerabilities faster?
Remember that vulnerability management is just one of the pillars of good cybersecurity hygiene. If you are layering it with FIM, EDR, and proper system hardening, then you’ve got a solid foundation. Yes, you have to make adjustments in some places, but remember that patches fix multiple vulnerabilities, that few vulnerabilities are ever actually exploited, and that known active exploitation increases risk. From there, a few simple choices will keep your VM program running smoothly.
If NIST successfully modernizes the NVD, what capabilities or improvements would have the biggest impact on organizations over the next five years?
First, we should talk about what modernization looks like. It’s better application of CPEs and CWEs. It’s inclusion of EPSS data alongside CVSS data. It’s providing better remediation guidance and a more structured list of external resources. My biggest fear is that OVAL will be seen as a useful standard and further adopted or that CPE data will continue to be less than complete. I’m not saying that everything needs better enrichment, but critical vulnerabilities need to be completely enriched and pulled out and better accessed. We need to deprioritize CVSS data. If we can start to make changes and improvements, then we may see a place where organizations can actually start to look for guidance. Right now, I would say that CISA Kev and CVE.org are a better combination of data than NVD, and I’m not sure anyone really needs to go to NVD. 10 years ago, NVD was at the top of the pecking order, and it would be interesting to see them return to that status.
Share this:
Like this:
Related
This entry was posted on August 12, 2026 at 8:00 am and is filed under Commentary with tags Fortra. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.