
Author: Gene Moody, Field CTO at Action1
AI can help us find vulnerabilities faster than ever before. But what happens when the rest of the vulnerability management ecosystem can’t keep up?
When the vulnerability volume exceeds the system
In April, NIST released a statement on updates to NVD operations, reflecting a necessary response to the scale. CVE volume has grown beyond what the current enrichment model was designed for. As part of the change, approximately 30,000 vulnerabilities that were published before March 1, 2026 were reclassified as “Unscheduled.”
Prioritization, automation and selective processing are fundamentally sensible adjustments. However, in practice, this shift brings with it a number of risks that may not be fully understood, particularly for those responsible for defending corporate environments.
The pressure is not theoretical. Action1’s 2026 Software Vulnerability Assessment Report found that the number of disclosed vulnerabilities in the enterprise software categories analyzed increased by 92% in 2025 compared to 2024. Critical and high-severity vulnerabilities each increased by 103%, while vulnerabilities that allow remote code execution increased by 128%.
Today, the volume of disclosures that need to be validated, enriched, prioritized, and ultimately remedied will likely place even greater pressure on systems designed for a slower era of vulnerability detection.
So the core problem is not simply the presence of a residue. Residues are an expected result in any system that is growing rapidly. The concern is how this backlog will be handled and, more importantly, what signals will be generated by the decision to prioritize newer vulnerabilities over older, unprocessed ones.
What happens if the enrichment is left behind?
By focusing enrichment efforts only on current CVEs, the system implicitly prioritizes vulnerabilities that may already be known, confirmed, and in some cases actively discussed by vendors or researchers, but which lack full NVD context.
This creates an information asymmetry of a particularly difficult kind: partial intelligence without the second half that makes it easy to implement. Security teams that rely heavily on NVD as a normalized source of vulnerability information may see incomplete or lagging data.
Attackers, on the other hand, do not have to wait for standardized enrichment before correlating vendor recommendations, security research, patch releases, exploit information, and public disclosures.
This gap is important because enrichment is not cosmetic. Structured metadata, affected platform information, severity rating, configuration details, and other contextual information enable defenders to determine whether a vulnerability actually applies to their environment and how urgently it should be remedied.
When this information is missing or delayed, companies are often forced to either wait for additional context or make decisions based on fragmented information. Neither outcome is ideal in a threat landscape where exploitation can occur faster than internal validation and remediation processes.
But that’s not all
There is also a second-order effect that is harder to quantify but just as important. A rolling backlog that is continually added and selectively removed at the same time creates uncertainty about coverage. Without a clear commitment to address older entries within a defined time frame, the backlog becomes semi-permanent.
Some vulnerabilities grow rapidly, others remain pending, and there is limited visibility into which category a given CVE falls into at any given time.
For practitioners, this makes prioritization excessively difficult. When affected product information, such as CPE data, is incomplete or too broad, companies are at higher risk of false positives. Teams may spend time investigating vulnerabilities that don’t apply to their environment and may miss risks that do.
Over time, this will certainly erode trust in the data set and force organizations to build alternative intelligence pipelines. This will result in additional costs, tools and operational complexity. Also, as one might predict, increasing failure rates.
Action1’s 2026 Software Vulnerability Ratings Report found that enterprise application utilization increased by 800% last year.
Discover which software categories saw the biggest changes in vulnerabilities, severity, and attacker activity.
Vulnerability management is changing
None of this suggests that NIST is acting irresponsibly. The scale issue is real and the existing model was not designed for the amount of vulnerability information now entering the ecosystem. But the compromise introduced shifts more responsibility downwards.
Organizations must rely less on a single authoritative source and rely more on the correlation of multiple sources, including NVD, vendor recommendations, independent vulnerability intelligence providers, threat intelligence platforms, and internal asset inventories.
When you zoom out, you come to the conclusion that vulnerability management is less about leveraging a curated list and more about synthesizing accurate information from incomplete data in near real-time. This requires maturity, tools and process discipline that not all companies currently have.
If this direction continues, NVD will remain an important part of the vulnerability management ecosystem, but will no longer function as a standalone, comprehensive baseline. Instead, it becomes one input among many that may fall well short of the reality of exploitation in this area.
The more important question is not simply: “What are the vulnerabilities?” but “Which of these affect us, which pose the greatest risk and how quickly can we act?”
How defenders should adapt
The first lesson is that vulnerability management can no longer rely on a single source of enrichment. NVD remains incredibly valuable, but security teams increasingly need to subscribe to cumulative work from vendors and organizations that synthesizes the available data into actionable intelligence
More importantly, collecting additional feeds is only part of the answer. More information may simply lead to another prioritization problem. The real goal is to convert fragmented vulnerability information into a decision: Does this vulnerability affect us, how urgent is it and what can we do about it now?
This is the model that Action1 has adopted Vulnerability management. Instead of relying solely on NVD enrichment, Action1 combines information from sources such as VulnCheckNVD++, NIST NVD, CISA’s KEV catalog, Microsoft’s own MSRC data, and vendor release notes, then scores each vulnerability based on CVE data, CVSS severity, CISA KEV status, and known use in ransomware campaigns, enabling initial prioritization in minutes.
This information is correlated with real-time endpoint data so teams can determine which vulnerabilities actually impact the software deployed in their environment and prioritize remediation accordingly.
Once an affected endpoint is identified, remediation should not require another export, manual correlation exercise, or lengthy handoff Patching begins.
Action1 unifies vulnerability assessment and remediation into a single workflow, enabling organizations to go from knowing a vulnerability exists to reducing the actual exposure much more quickly, all from a single console.

The era of AI vulnerabilities will be defined not by how quickly IT and security teams can find vulnerabilities, but how quickly they can understand, prioritize and remediate them. Discovery is accelerating, and so must remediation.
Learn how Action1 combines real-time operating system and third-party vulnerability intelligence with automated remediation to help your team reduce exposure faster.
Start for free and scale when you’re ready.
Sponsored and written by Action1.
