NIST issues RFI for modernizing because of AI!
DarkReading.com reported that on August 12 NIST issued “The "Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence" comes as the agency is dealing with a massive influx of vulnerabilities, partly caused by AI enabling researchers to investigate and discover flaws at a faster pace.” The August 14, 2026 article entitled “Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI” (https://www.darkreading.com/vulnerabilities-threats/ai-driven-bug-tsunami-nist-looks-to-ai) included these comments:
"Today's vulnerability management ecosystem is rapidly evolving and is characterized by AI-enabled cyber tools and accelerated technology delivery cycles," the agency stated in the RFI. "Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities. The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent."
NIST specifically asks how AI and other automated mechanisms can be used to improve contextual risk prioritization, and if AI systems have a role in automated vulnerability remediation. The RFI is the latest effort instituted by the agency to keep up with a growing backlog of vulnerabilities, a problem that has been exacerbated by cuts to NIST and its programs in the past 18 months. In April, the US agency announced it would prioritize enrichment for vulnerabilities that appear on CISA's Known Exploited Vulnerabilities (KEV) list, flaws in software in use by the federal government, and security issues in critical software as defined by Executive Order 14028.
Anyone surprised by this RFI?