Back to Feed
PolicyAug 17, 2026

NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment

NIST seeks public input on AI's role in modernizing the National Vulnerability Database.

Summary

NIST has issued a Request for Information (RFI) to gather community input on how AI can improve the National Vulnerability Database (NVD). This comes after years of automation promises failed to address a growing backlog and reduced enrichment scope. NIST also disclosed an unreleased AI tool, V-etalon, intended to aid in vulnerability information enrichment, though its exact function and integration into the NVD workflow remain unclear.

Full text

Back[Security News]NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE EnrichmentNIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.Sarah GoodingAug 17, 2026|9 min readThe National Institute of Standards and Technology is asking the cybersecurity community how artificial intelligence should reshape the National Vulnerability Database, more than two years after the agency began publicly pointing to automation as a solution for its growing vulnerability processing problems.The Request for Information seeks input on improving the NVD's "scalability, automation, interoperability, transparency, and utility." A separate NIST blog post accompanying the RFI disclosed that the agency has begun developing an AI-enabled tool called V-etalon.The announcement arrives four months after NIST moved most CVEs outside routine enrichment, and less than three months after a federal audit found that the agency had no strategic plan for the NVD, no workable plan to clear its backlog, and no sustainable process for keeping pace with new submissions.NIST is now seeking public comments to inform its "future strategic planning efforts." The agency is asking stakeholders to help shape a strategy after years of missed deadlines, abandoned proposals, shrinking enrichment commitments, and repeated assurances that automation was being explored.NIST Has Not Released V-etalon#NIST offered one paragraph about V-etalon under the heading "Steps We've Already Taken":We have already begun work on a tool, called V-etalon, that leverages AI technologies to aid in enriching vulnerability information. We hope that V-etalon will eventually provide a foundation for the evaluation of vulnerability information. We will be looking for feedback and collaboration opportunities once it’s available, all via GitHub (please stay tuned for an upcoming release and announcement).The disclosure provides no release date, repository, documentation, architecture, evaluation results, or description of which enrichment fields the tool will address. NIST does not say whether V-etalon will generate CVSS scores, identify CWEs, build CPE applicability statements, validate data supplied by CVE Numbering Authorities, or perform some other function.Even its intended role remains unclear. NIST says the tool will "aid in enriching vulnerability information," then describes it as a possible foundation for evaluating vulnerability information. Those are different jobs, and the agency does not explain how V-etalon would enter the NVD's production workflow or how human analysts would review its output.The full RFI asks the public which vulnerability management tasks are suitable for AI, which should require human review, what safeguards are needed, and how AI-driven decisions can remain transparent and auditable. Those are foundational design questions for the tool NIST says it has already begun building.Automation Has Been on the Roadmap Since 2024#NIST has been presenting technology and automation as the long-term answer to the NVD's capacity problems since the backlog first became visible.In May 2024, while promising to clear the backlog by the end of that fiscal year, NIST said it was working on "technology and process updates" to support the automation of vulnerability management, security measurement, and compliance. The agency missed that deadline, and federal auditors later found that meeting it would have required NIST to process about 6,200 vulnerabilities per month, above both its historical output and its estimated maximum capacity.In November 2024, after the backlog passed 20,000 CVEs, NIST said it was "developing new systems" to process data from Authorized Data Publishers more efficiently. NIST did subsequently deploy support for ingesting ADP data, including enrichment supplied by CISA. That change improved data ingestion and attribution, but it did not automate the NVD's core enrichment work.By March 2025, NIST was "exploring the use of machine learning to automate certain processing tasks". It identified no tasks, tools, milestones, or delivery dates. At VulnCon the following month, NVD leaders described pilot tools for Linux kernel CVE enrichment and research into machine learning and AI-backed methods. NIST did not link to a public pilot or announce a production deployment.In April 2026, NIST again cited "automated systems and workflow enhancements" as necessary for long-term sustainability. The announcement included no technical details or timeline. It accompanied the agency's decision to stop routinely enriching most CVEs.V-etalon gives that recurring automation plan a name. The announcement still leaves the same central questions unanswered: what the system does, how well it works, when the public can inspect it, and when it will change NVD output.NIST Is Enriching Fewer CVEs#The NVD already automates the easy part of its pipeline. According to the RFI, CVE records are ingested within approximately one hour of publication. NVD analysts then perform the enrichment that makes those records operationally useful, including assigning severity information and identifying affected product versions.That second stage has been a perennial bottleneck for the NVD. In April, NIST abandoned its longstanding goal of analyzing every CVE. The agency now prioritizes CVEs in CISA's Known Exploited Vulnerabilities catalog, vulnerabilities affecting software used by the federal government, and vulnerabilities in software designated as critical under Executive Order 14028. Other CVEs can be placed in "Not Scheduled" status and considered later as resources allow.NIST also stopped routinely producing an independent CVSS score when a CNA has supplied one, limited reanalysis of modified CVEs, and moved backlogged records published before March 1, 2026 into "Not Scheduled." NIST said CVE submissions had increased 263% between 2020 and 2025, while the nearly 42,000 CVEs it enriched in 2025 still failed to keep pace.The August RFI describes demand for near-real-time enrichment at the same time the NVD is providing routine enrichment for a narrower share of the vulnerability stream. V-etalon is being presented as a possible bridge between those positions, but NIST has supplied no evidence yet that the tool can close that gap.Not Scheduled CVEs Outnumber Active Enrichment Nearly 14 to 1#The NVD dashboard shows how that reduced enrichment scope is reflected in the current data. As of August 17, the database had received 53,115 new CVEs in 2026 and enriched 30,531. During August, it had received 6,092 new CVEs and enriched 2,246.The status counts show a much larger body of records outside the active enrichment queue. NIST listed 42,353 CVEs as "Not Scheduled," compared with 2,426 "Awaiting Enrichment" and 623 "Undergoing Enrichment." The Not Scheduled category was nearly 14 times larger than the two active enrichment queues combined.Those CVEs remain available through the NVD, but they are outside scheduled analysis unless they meet NIST's prioritization criteria or are selected for enrichment as resources allow.The RFI Starts Where the Audit Ended#The Commerce Department Office of Inspector General's May audit found that NIST "does not have sustainable processes to manage NVD submissions" and would be unable to clear the backlog or prevent future processing delays without significant changes.Auditors found that NIST had no strategic plan when they requested one. The backlog grew from about 13,000 vulnerabilities in June 2024 to more than 27,000 by the end of 2025. NIST and CISA also duplicated at least 21,000 enrichment activities between May 2024 and December 2025, in some cases using the same contractor. OIG estimated that the duplication wasted approximately $200,000.The audit recommended that NIST create a strategic plan, establish a backlog management plan with milestones and a target date, red

Entities

National Vulnerability Database (product)NIST (vendor)Artificial Intelligence (technology)V-etalon (product)CVE (product)CVSS (product)