NIST Narrows the National Vulnerability Database as CVE Backlog Becomes Unmanageable
What Happened
NIST announced it will only enrich CVEs that appear in CISA's Known Exploited Vulnerabilities catalog or impact federal and critical-infrastructure systems. The shift follows a 2024 funding lapse and record CVE submission volume, much of it AI-assisted discovery.
My Take
AI is breaking the vulnerability-disclosure pipeline the same way it is breaking academic peer review — more output than any human institution was designed to process. The practical consequence: enterprises can no longer outsource severity judgment to a government feed and must fund their own AI-native triage. Budget this as a new line in 2026 security planning, because the gap between "CVE assigned" and "CVE understood" is about to widen by an order of magnitude, and attackers will live in that gap.
Read Original Source