NIST Seeks AI Solutions to Combat 'Bug Tsunami' Overwhelming Vulnerability Database
The agency issued a Request for Information to modernize the NVD as AI-driven discovery pushes vulnerability reports to record highs.
The National Institute of Standards and Technology (NIST) is turning to artificial intelligence to prevent its primary vulnerability catalog from being buried under a mountain of data. On August 12, 2026, NIST issued a Request for Information (RFI) seeking public input on how to modernize the National Vulnerability Database (NVD) using AI and automation to handle an unprecedented surge in software flaw reports.
This move comes as the industry faces what experts describe as an "AI-driven bug tsunami." According to data from CVE.ICU, reported software vulnerabilities surged by more than 72% in the first eight months of 2026 compared to the same period in 2025, totaling 50,340 cases. NIST aims to determine if AI can be integrated into the NVD to improve risk prioritization and automate vulnerability remediation, allowing the agency to process this massive influx of data more efficiently.
A System Under Strain
The NVD has struggled for over two years with significant enrichment backlogs, where the process of adding critical analysis and severity scores to reported bugs has lagged behind the rate of discovery. The situation became critical enough that in April, NIST was forced to narrow its enrichment focus. The agency now prioritizes high-impact vulnerabilities, specifically those appearing on the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) list and critical software defined by Executive Order 14028.
The Signal-to-Noise Challenge
For cybersecurity professionals, the primary challenge is no longer the quantity of reported bugs, but the ability to distinguish truly exploitable threats from low-severity noise. The risk is that a flood of reports creates a "denial of service" effect for security teams. If NIST can successfully integrate AI for triage without sacrificing human verification, it can maintain the NVD as a trusted, neutral government standard. However, failure to do so risks pushing the burden of reliability onto the end-users.
Trey Ford, Chief Strategy and Trust Officer at Bugcrowd, emphasizes the unique role of the NVD. "The trust value of the NVD is precisely that it is government-run," Ford said. "It is neutral, non-profit, and lacks the vendor incentives to under- or over-estimate severity."
The Reliability Trade-off
While AI offers a path to scalability, industry experts warn against total automation. Ford noted that if NIST relies on AI to fill gaps without maintaining a human verification layer, the resulting data may become faster but less reliable.
What remains to be seen is how NIST will balance this need for speed with the necessity of accuracy. The agency's next steps will depend on the responses to the RFI, as it seeks a framework that leverages automation to triage the "tsunami" of reports while preserving the human-led verification that gives the NVD its authority.