NIST Seeks Overhaul of National Vulnerability Database for AI Era
NIST is soliciting public input to modernize its National Vulnerability Database (NVD) to address the growing challenges posed by AI-driven vulnerability discovery and exploitation.

The National Institute of Standards and Technology (NIST) has initiated a significant effort to modernize its National Vulnerability Database (NVD), seeking public input on how to adapt its processes for an era increasingly defined by artificial intelligence and machine-consumable security data. In a request for information (RFI) published in the Federal Register, NIST acknowledged that its NVD, a cornerstone for coordinating vulnerability identification and remediation, must evolve to keep pace with AI's accelerating impact on cybersecurity.
The agency's concern stems from the growing capabilities of large language models and other AI tools in discovering and exploiting software vulnerabilities at scale. NIST highlighted that traditional vulnerability management approaches, characterized by periodic scanning, static prioritization, and manual remediation, are becoming increasingly inadequate. The RFI points to a surge in the volume and complexity of disclosed vulnerabilities, coupled with inconsistent data quality and a heightened reliance on automation and machine-readable security data, as evidence of this shift.
NIST views these challenges not just as obstacles but as opportunities to transform the vulnerability management ecosystem through proactive reforms and NVD innovation. The RFI poses a series of targeted questions to gather insights from stakeholders across the cybersecurity community. Key areas of inquiry include how defenders can better leverage automation in the vulnerability reporting process, what capabilities and processes are needed for more rapid dissemination of threat information to relevant parties, and how to ensure transparency and auditability in AI-driven decision-making.
Furthermore, NIST is exploring the potential role of AI in automated vulnerability remediation. The agency aims to foster a "future-ready vulnerability management ecosystem that is continuous, contextual, and automated," enabling cybersecurity practices to respond effectively to real-world threats and align with business priorities. This initiative underscores a broader governmental push to integrate AI responsibly into national security and cybersecurity frameworks.
This effort by NIST to revamp its vulnerability database comes shortly after the Trump administration launched "Gold Eagle," a federal clearinghouse managed by the Department of Treasury for sharing AI threat information between government and the private sector. Additionally, the White House has partnered with Carnegie Mellon’s Software Engineering Institute to develop the Vulnerability Information and Coordination Environment (VINCE), which will focus on collecting and distributing reports on vulnerabilities discovered by AI systems.
The RFI's questions are designed to elicit practical solutions and strategic guidance. NIST is asking for input on how to improve the timeliness and accuracy of vulnerability data, the development of standardized formats for machine-readable vulnerability information, and the integration of threat intelligence to provide more contextualized data. The agency also seeks to understand the ethical considerations and potential biases associated with using AI in vulnerability management.
Ultimately, NIST's initiative aims to ensure that the NVD remains a vital and effective resource in an increasingly complex and rapidly evolving threat landscape. By embracing AI and automation, NIST hopes to enhance the speed, accuracy, and comprehensiveness of vulnerability information, thereby strengthening the nation's overall cybersecurity posture against emerging threats.
The public comment period for the RFI is expected to be open for a specified duration, after which NIST will analyze the feedback to inform the development of its updated strategy for the National Vulnerability Database.