August 30, 2026•4 min read

AI Accelerates Vulnerability Discovery, But Defenses Struggle

AI's role in accelerating vulnerability discovery is transforming cybersecurity, but it presents challenges for defenders. Discover ways organizations can adapt.

Cybersecurity professionals reviewing vulnerability data on multiple computer screens in a modern office setting.

Rising Challenges in Vulnerability Management

Recent advancements in artificial intelligence (AI) are dramatically accelerating vulnerability discovery, yet this rapid pace puts increasing pressure on existing vulnerability management frameworks. A stark warning was issued by the National Institute of Standards and Technology (NIST) in April 2026 regarding the growth of vulnerabilities outlined in the National Vulnerability Database (NVD). The agency has observed that the volume of Common Vulnerabilities and Exposures (CVEs) has reached an unsustainable level for the current enrichment model.

The NIST statement indicated that approximately 30,000 vulnerabilities published before March 1, 2026, were reclassified as "Not Scheduled." This significant update reflects a problematic scenario for security teams tasked with managing vulnerabilities amid an overwhelming influx of new information.

Vulnerability Growth Statistics

YearOverall Vulnerability IncreaseCritical Vulnerabilities IncreaseRemote Code Execution Vulnerabilities Increase
2024–––
202592%103%128%

According to Action1's 2026 Software Vulnerability Ratings Report, the number of disclosed vulnerabilities across various enterprise software categories spiked dramatically. Specifically, there was a 92% increase in overall vulnerabilities in 2025 compared to the previous year, while critical and high-severity vulnerabilities also increased by 103% each, and those allowing remote code execution surged by 128%.

The Burden of Overwhelming Backlogs

The rise in vulnerability disclosures has resulted in backlogs that are becoming synonymous with vulnerability management. While backlogs are anticipated in fast-evolving systems, the issue here is the management of those backlogs and how organizations prioritize vulnerabilities. A lack of clear feedback mechanisms can lead to unchecked growth in backlogs, creating a situation where older vulnerabilities are deprioritized in favor of newer ones.

This trend leads to a situation rife with potential risks. Vulnerabilities that are known and acknowledged may not receive timely updates or enrichment, leaving security teams without the necessary context that aids in determining the urgency of a given vulnerability. This, in essence, introduces an information gap — attackers don't wait for updates, and a lack of visibility could result in critical vulnerabilities remaining unaddressed. As a consequence, even established security teams may face growing difficulty in accurately determining which vulnerabilities require immediate attention.

The Dangers of Incomplete Information

Focusing on recent CVEs neglects the backlog of older vulnerabilities that may still pose threats. Security teams often depend on the NVD as a primary information source, assuming it is a normalized standard of data on vulnerabilities. When enrichment fails to keep pace, teams are left with partial intelligence that does not provide actionable insights. Missing structured metadata, severity scores, and relevant platform information complicates the decision-making process.

Second-Order Effects of Management Backlogs

The ongoing accumulation of vulnerabilities, coupled with a lack of effective remediation strategies, creates uncertainty in coverage. As some vulnerabilities receive timely attention while others languish without priority, the visibility into the overall landscape becomes murky. This environment sows confusion, rendering the task of prioritization more complicated than ever.

Inaccuracies in affected-product information can lead to false positives, requiring security teams to spend resources investigating non-relevant vulnerabilities. As trust in the dataset erodes, organizations may seek alternative intelligence resources, leading to increased operational complexity and challenges in maintaining efficiency.

A cybersecurity expert outlining the impact of backlogs on vulnerability management strategies.

Adapting to a New Vulnerability Landscape

Strategies must evolve as the dynamics of vulnerability management change. NIST's shift in approach certainly reflects a recognition of the scale problem currently affecting vulnerability databases. However, it also places greater responsibility on organizations to navigate multiple intelligence sources for a more nuanced understanding of vulnerabilities.

Organizations must embrace a broader spectrum of data sources instead of relying solely on NVD for information. This includes incorporating vendor advisories, independent vulnerability intelligence providers, and threat intelligence platforms alongside their internal asset inventories. Vulnerability management is transforming from simple consumption of curated lists to integrating various sources of fragmented information to synthesize actionable intelligence in real time.

Action1's Robust Approach to Vulnerability Management

To address these evolving challenges, Action1 has developed a novel strategy for effective vulnerability management. Rather than depending exclusively on the NVD for enrichment, Action1 integrates intelligence from multiple sources, such as VulnCheckNVD++, CISA’s KEV Catalog, Microsoft’s MSRC data, vendor release notes, and CVE data combined with CVSS severity and CISA KEV status.

This multi-source approach allows for efficient scoring of vulnerabilities, providing an initial prioritization in mere minutes. Coupled with real-time endpoint data, security teams can identify which vulnerabilities directly impact their deployed software, enabling them to prioritize remediation efforts effectively. This comprehensive model streamlines the transition from vulnerability discovery to actual patching, ensuring that organizations can reduce exposure promptly.

Key Takeaways

  • The volume of disclosed vulnerabilities increased by 92% in 2025.
  • Critical and high-severity vulnerabilities each surged by over 103%.
  • Effective vulnerability management necessitates a multi-source approach.
  • Action1's model allows quick priority assessment and remediation of vulnerabilities.

Conclusion: Preparing for the Future

As the landscape of vulnerability discovery continues to evolve, organizations must adapt their strategies accordingly. The ability to understand, prioritize, and patch vulnerabilities will define success in the age of rapid AI-driven vulnerability discoveries. Moving forward, the focus should be on synthesizing actionable intelligence from diverse sources to ensure vigorous defenses against emerging threats.

Frequently Asked Questions

NIST reclassified roughly 30,000 vulnerabilities as 'Not Scheduled' due to the excessive volume overwhelming the current enrichment model.
#AI#Cybersecurity#Vulnerability Management#NIST#Vulnerability Discovery