Skip to content
Tech News
← Back to articles

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

read original more articles
Why This Matters

The rapid acceleration of vulnerability discovery driven by AI presents both opportunities and challenges for the tech industry. While AI enables faster identification of security flaws, existing vulnerability management systems risk being overwhelmed, potentially leaving critical vulnerabilities unaddressed. This underscores the urgent need for improved prioritization and automation strategies to keep pace with the growing volume of threats, ensuring better protection for consumers and enterprise environments alike.

Key Takeaways

Author: Gene Moody, Field CTO at Action1

AI can help us find vulnerabilities faster than ever. But what happens when the rest of the vulnerability management ecosystem can’t keep up?

When Vulnerability Volume Outpaces the System

In April, NIST released a statement regarding updates to NVD operations that reflects a necessary response to scale. CVE volume has grown beyond what the current enrichment model was designed to handle. As part of the change, roughly 30,000 vulnerabilities published before March 1, 2026, were reclassified as "Not Scheduled."

Prioritization, automation, and selective processing are reasonable adjustments in principle. In practice, however, the shift introduces a set of risks that may not be fully understood, particularly for those responsible for defending enterprise environments.

The pressure is not theoretical. Action1's 2026 Software Vulnerability Ratings Report found that disclosed vulnerabilities across the enterprise software categories analyzed increased 92% in 2025 compared with 2024. Critical and high-severity vulnerabilities increased 103% each, while vulnerabilities enabling remote code execution increased 128%.

Today, the volume of disclosures that must be validated, enriched, prioritized, and ultimately remediated is likely to place even greater pressure on systems designed for a slower era of vulnerability discovery.

The core issue is therefore not simply the existence of a backlog. Backlogs are an expected outcome in any system operating under rapid growth. The concern is how that backlog is managed and, more importantly, what signals are created by the decision to prioritize newer vulnerabilities over older, unprocessed ones.

What Happens When Enrichment Falls Behind

By focusing enrichment efforts only on recent CVEs, the system implicitly deprioritizes vulnerabilities that may already be known, confirmed, and, in some cases, actively discussed by vendors or researchers but lack full NVD context.

... continue reading