Navigating the Vulnerability Management Alphabet Soup: The NVD’s Call for AI Feedback
Decoding the Acronyms: CVE vs. NVD
To truly grasp the significance of this RFI, it is essential to untangle the acronyms that define coordinated vulnerability disclosure (CVD). While often used interchangeably, these programs serve distinct purposes:
- CVE (Common Vulnerabilities and Exposures): Managed primarily via cve.org, the CVE program serves as the global dictionary for identifying and cataloging technical vulnerabilities. Although funded by the U.S. Department of Homeland Security (DHS) through CISA and operated by the MITRE Corporation, it is fundamentally an international, volunteer-led initiative. Through hundreds of CVE Numbering Authorities (CNAs)—ranging from vendors to researchers—vulnerabilities are assigned their unique identifiers (e.g., CVE-2026-1234). Today, an unassigned software vulnerability is an extreme rarity.
- NVD (National Vulnerability Database): Operating strictly as a federal program under NIST, the NVD functions as the contextual engine for CVEs. It enriches raw vulnerability identifiers with critical metadata, including Common Vulnerability Scoring System (CVSS) severity metrics, Common Weakness Enumeration (CWE) classifications, and Common Platform Enumeration (CPE) strings. Notably, the NVD maintains the authoritative CPE database—a notoriously complex undertaking in software identification.
In short: The CVE program provides the name and baseline description, while the NVD provides the vital operational context (severity and weakness type).
The Bottleneck: When Human Curation Fails
Unfortunately, the NVD has struggled to maintain consistent enrichment over the past two years. Beginning in 2024, the sheer volume of vulnerability disclosures simply overwhelmed the database’s human-curated processes. Exacerbated by funding constraints, this operational bottleneck has severely impacted the U.S. federal government and private sector organizations that heavily rely on downstream NVD data to prioritize patching.
Industry data—such as insights shared during recent VulnCheck webcasts—suggests that the NVD’s manual processing capacity is effectively capped at roughly 30,000 vulnerabilities annually. Meanwhile, AI tooling is simultaneously accelerating the rate at which attackers and researchers discover new flaws. Because the disclosure pipeline will only continue to surge, the NVD must urgently transition to “machine-speed” processing to survive.
AI: The Catalyst and the Cure
Integrating Large Language Models (LLMs) to automate vulnerability summarization, categorization, and scoring presents both immense promise and significant hurdles. High-quality AI tooling is expensive—a stark challenge for a program with limited funding—and its outputs are prone to hallucinations, making them difficult to trust implicitly. Through the current RFI, the NVD is directly asking non-federal industry experts how it should best allocate its limited energy and resources to safely modernize these critical operations.
The Bigger Picture: Redundancy vs. Consolidation
This RFI also opens the door to a more existential debate: Should the NVD continue its enrichment program at all?
Following the NVD’s visible operational degradation in February 2024, CISA stepped in by launching the “Vulnrichment” program in January 2025. While Vulnrichment effectively processes most CVE metadata, CISA quickly discovered that generating accurate CPEs is exceptionally difficult—a specialized task that the NVD is uniquely equipped to handle.
Having two separate federal entities (CISA within DHS, and NIST within the Department of Commerce) performing overlapping enrichment tasks might appear to be bureaucratic duplication. However, in enterprise systems design, redundancy is often a virtue. This dual-agency approach may serve as a highly effective hedge against future funding crises or operational single points of failure.
A Call to Action for Security Experts
The vulnerability management ecosystem is at a crossroads. This RFI covers extensive technical ground, and while few professionals possess deep expertise across all domains discussed, even targeted feedback is invaluable. If you have informed opinions on the future of vulnerability enrichment, AI integration, or federal cyber redundancy, ensure your voice is heard by submitting your comments to NIST before the October 13, 2026 deadline.
About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


