started · updated
NIST seeks public input to modernize National Vulnerability Database using AI
The National Institute of Standards and Technology (NIST) has issued a request for information (RFI) to modernize the National Vulnerability Database (NVD) in response to the rise of artificial intelligence. The agency is seeking input from government and industry stakeholders on how to evolve vulnerability management over the next five years.
NIST aims to create a future-ready ecosystem that is “continuous, contextual, and automated.” The RFI addresses concerns that traditional manual remediation and static prioritization are becoming inadequate as malicious actors use AI to discover and exploit vulnerabilities at scale. The agency is specifically investigating how AI can be integrated into the vulnerability lifecycle while maintaining human oversight, transparency, security, and data quality.
The inquiry covers seven key areas, including process automation, risk assessment, and the balance between AI-driven prioritization and human review. The NVD serves as a foundational repository for the U.S. government and the private sector, ingesting Common Vulnerabilities and Exposures (CVE) records and enriching them with severity scores and product details. Comments on the RFI will be accepted through October 13, 2026.
Entities
Common Vulnerabilities and Exposures · National Institute of Standards and Technology · National Vulnerability Database