Author: Gene Moody, Action1 Field CTO
Artificial intelligence is helping security teams discover vulnerabilities faster than ever. But what happens when vulnerability management systems can no longer keep pace with the volume of new threats?
AI Is Accelerating Vulnerability Discovery. Can Vulnerability Management Keep Up?
When the volume of vulnerabilities overwhelms existing systems
In April, NIST announced updates to its National Vulnerability Database (NVD) operations to support the growing volume of vulnerability data. The number of CVEs has increased beyond what existing enrichment models were designed to manage. As part of these changes, approximately 30,000 vulnerabilities disclosed before March 1, 2026, were reclassified as “not addressed.”
Prioritization, automation, and selective processing are reasonable responses to a rapidly expanding workload. In practice, however, these changes introduce risks that are not yet fully understood—particularly for security teams responsible for protecting enterprise environments.
The pressure is not theoretical. According to Action1’s 2026 Software Vulnerability Assessment Report, vulnerabilities disclosed across the enterprise software categories analyzed increased by 92% in 2025 compared with 2024. Critical and high-severity vulnerabilities each increased by 103%, while vulnerabilities that enable remote code execution increased by 128%.
The volume of new disclosures that must be verified, assessed, prioritized, and remediated is placing additional strain on vulnerability management processes designed for a slower threat landscape.
The central issue is not simply the existence of a vulnerability backlog. Backlogs are an expected consequence of systems operating under rapid growth. The more important concern is how that backlog is managed—and what signals are created when newer vulnerabilities are prioritized over older, unresolved vulnerabilities.
What happens when vulnerability intelligence is delayed?
By focusing enrichment efforts primarily on recent CVEs, vulnerability management systems may unintentionally deprioritize older vulnerabilities that are already known, confirmed, and actively discussed by vendors and security researchers but lack complete NVD context.
This creates a difficult information gap. Security teams may receive partial vulnerability intelligence without the additional context needed to make immediate, actionable decisions. Organizations that rely heavily on the NVD as a central source of vulnerability information could encounter incomplete or delayed data.
Attackers, however, do not need to wait for standardized enrichment. They can correlate vendor advisories, security research, software patches, exploit information, and public disclosures independently.
This gap matters because vulnerability context is essential. Structured metadata, affected-platform information, severity scores, configuration details, and related intelligence help defenders determine whether a vulnerability affects their environment and how quickly they need to respond.
When that information is missing or delayed, organizations may have to wait for additional context or piece together fragmented intelligence from multiple sources. Neither option is ideal in a threat environment where exploitation can move faster than internal validation and remediation processes.
The hidden risks of a growing vulnerability backlog
There are also second-order effects that are more difficult to quantify but equally important. A rolling vulnerability backlog that is continuously replenished while being selectively reduced creates uncertainty about overall coverage. Without a clear commitment to processing older entries within a defined timeframe, the backlog can become a permanent feature of the vulnerability management process.
Some vulnerabilities may be enriched and remediated quickly, while others remain unresolved. In many cases, security teams have limited visibility into which category a particular CVE falls into at any given time.
For security practitioners, this makes vulnerability prioritization significantly more complex. If information about affected products—such as Common Platform Enumeration (CPE) data—is incomplete or too broad, organizations face a greater risk of false positives. Teams may spend valuable time investigating vulnerabilities that do not affect their environments while overlooking risks that do.
Over time, inconsistent or incomplete vulnerability data can erode trust in the dataset and force organizations to build alternative vulnerability intelligence pipelines. This adds tools, costs, and operational complexity while increasing the likelihood of mistakes.
According to Action1’s 2026 Software Vulnerability Assessment Report, enterprise application exploitation soared by 800% last year.
Explore the software categories that experienced the greatest changes in vulnerabilities, severity, and attacker activity.
Vulnerability management is changing
None of this suggests that NIST is acting irresponsibly. The scale of the challenge is real, and existing vulnerability enrichment models were not designed to handle the volume of information now entering the ecosystem. However, the resulting trade-offs place greater responsibility on security teams and downstream technology providers.
Instead of relying on a single source of truth, organizations will increasingly need to correlate information from multiple sources, including the NVD, vendor advisories, independent vulnerability intelligence providers, threat intelligence platforms, and internal asset inventories.
At a broader level, vulnerability management is shifting away from relying on a single curated list. It is becoming a process of synthesizing accurate, actionable intelligence from incomplete data in near real time. This requires mature processes, effective tools, and operational discipline that not every organization currently has.
If this trend continues, the NVD will remain an important part of the vulnerability management ecosystem, but it may no longer provide a complete baseline on its own. Instead, it will become one source among many and may lag behind real-world exploitation activity.
The most important question is therefore no longer simply, “What vulnerabilities exist?” It is: “Which vulnerabilities affect our environment, which represent the greatest risk, and how quickly can we take action?”
How security teams can adapt to the changing threat landscape
The first lesson is that vulnerability management can no longer depend on a single source of vulnerability intelligence. While the NVD remains valuable, security teams increasingly need to combine its data with the work of vendors and organizations that aggregate vulnerability information into actionable intelligence.
However, collecting more vulnerability feeds is only part of the solution. More data can create a different prioritization challenge if it is not translated into clear decisions. The real objective is to answer three questions: Does this vulnerability affect our environment? How urgent is it? What can we do about it now?
This is the model adopted by Action1 Vulnerability Management. Rather than relying solely on NVD enrichment, Action1 combines intelligence from sources such as VulnCheckNVD++, the NIST NVD, CISA’s KEV catalog, Microsoft’s MSRC data, and vendor release notes.
Action1 scores vulnerabilities using CVE information, CVSS severity, CISA KEV status, and known use in ransomware campaigns to support initial prioritization within minutes.
This intelligence is correlated with real-time endpoint data, enabling teams to identify which vulnerabilities actually affect the software deployed in their environments and prioritize remediation based on real-world exposure.
Once affected endpoints are identified, remediation should not require separate exports, manual data correlation, or lengthy handoffs. Patch management can begin immediately.
Action1 combines vulnerability assessment and remediation in a unified workflow, helping organizations move from vulnerability identification to risk reduction faster through a single console.

The era of AI-powered vulnerability discovery will not be defined solely by how quickly IT and security teams can identify flaws. It will be defined by how quickly they can understand, prioritize, and remediate them. Discovery is accelerating, and vulnerability remediation must accelerate with it.
See how Action1 combines real-time operating system and third-party vulnerability intelligence with automated remediation to help teams mitigate security exposures faster.
Get started for free and scale when you’re ready.
Sponsored and written by Action1.
Source: www.bleepingcomputer.com


