NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment
Blog post from Socket
NIST has issued a Request for Information on modernizing the National Vulnerability Database, seeking input on AI, automation, interoperability, transparency, and the broader vulnerability-management lifecycle while disclosing an unreleased AI-assisted enrichment tool called V-etalon. The initiative follows years of automation promises, missed backlog targets, and a May federal audit that found NIST lacked sustainable processes, a strategic plan, and an effective backlog-clearing approach. Since April 2026, NIST has limited routine CVE enrichment to prioritized vulnerabilities, leaving many others marked “Not Scheduled”; as of August 17, that category contained 42,353 CVEs, nearly 14 times the number in active enrichment queues. Although NIST can ingest CVE records quickly, analyst-intensive tasks such as severity scoring and Common Platform Enumeration applicability mapping remain bottlenecks, with CPE work especially difficult and consuming substantial enrichment time. The RFI also addresses coordination with CISA, external data contributions, remediation, standards, and a five-year NVD vision, while critics note that existing sources already provide much vulnerability information but are not consistently integrated with organizations’ own asset inventories. Comments are due October 13, 2026, but NIST has not provided a release date, technical details, performance evidence, or operational plan for V-etalon.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Data Pipeline | 1 | 1,290 | 393 | 99 | +171% |
| Real-time | 1 | 13,979 | 3,441 | 296 | +113% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.