← 返回简报

NIST Opens National Vulnerability Database Modernization to Public Comment

Unite.AI · 2026-08-12 07:46

Regulation

NIST Opens National Vulnerability Database Modernization to Public Comment

Add Unite.AI to your preferred sources on GoogleThe National Institute of Standards and Technology is asking the public how to rebuild the National Vulnerability Database for an era of artificial intelligence, opening a 62-day comment window on August 12, 2026 that closes October 13, 2026 at 11:59 p.m. Eastern Time. The request for information published in the Federal Register seeks input on the NVD’s scalability, automation, interoperability, transparency, and utility, and on where AI should, and should not, be trusted inside the vulnerability management pipeline.

The NVD is the U.S. government repository of standards-based vulnerability management data, established and operated by NIST’s Information Technology Laboratory. It ingests records from the Common Vulnerabilities and Exposures program within roughly an hour of publication, then enriches them with severity scores and affected-product detail that security tools consume through its web interface and APIs. The notice describes it as a foundational resource for vulnerability management, software security, compliance automation, and cybersecurity risk analysis across the public and private sectors.

The RFI is explicit about why NIST is acting. The notice describes an ecosystem shaped by AI-enabled cyber tools and accelerated delivery cycles, in which malicious actors may use AI systems to discover and exploit vulnerabilities at scale. Traditional approaches built on periodic scanning, static prioritization, and manual remediation, it says, are showing their inadequacy. NIST frames the goal as a future-ready vulnerability management ecosystem that is “continuous, contextual, and automated.”

Seven Areas of Questions, From Triage to Remediation

The notice organizes its questions into seven areas. On process, it asks where AI-enabled automation belongs in the vulnerability lifecycle and which tasks should stay under human review. On risk assessment, it asks how contextual prioritization should work and how transparency and auditability in AI-driven prioritization decisions could be enhanced. On remediation, it asks what role AI systems should play in generating fixes, what safeguards would catch erroneous AI-generated remediations, and what blocks organizations from patching even when they receive prompt and complete vulnerability information.

Two sections reach beyond day-to-day operations. One asks whether existing identifiers, product naming schemes, and severity scoring systems are sufficient for actionable prioritization in the AI era, and what gaps remain in machine-readable vulnerability data. The other asks respondents to define what the NVD should become: which capabilities and services would increase its impact over the next five years, which emerging trends it should anticipate, and what metrics should track whether modernization succeeds.

Responses will inform strategic planning, technical architecture decisions, standards and best practices development, data governance, and community collaborations, the notice says. Comments must be filed electronically through regulations.gov under docket NIST-2026-0100; NIST will not accept submissions by postal mail, fax, or email, and all comments are posted publicly without redaction. The notice cautions commenters not to include personal or confidential business information.

A Database Already Under Strain

The RFI lands four months after NIST conceded it could no longer keep pace with the database’s core workload. In an April 15, 2026 announcement, the agency disclosed that CVE submissions rose 263% between 2020 and 2025, and that submissions in the first three months of 2026 ran nearly one-third higher than the same period a year earlier. NIST enriched nearly 42,000 CVEs in 2025, 45% more than any prior year, and still could not clear a backlog of unenriched records that had been building since early 2024.

The response was a triage model. NIST now prioritizes enrichment for CVEs in CISA’s Known Exploited Vulnerabilities catalog — with a goal of enriching those within one business day — along with CVEs affecting software used in the federal government and critical software as defined by Executive Order 14028, the Biden administration’s 2021 directive on federal cybersecurity. Everything else is listed but labeled “Lowest Priority – not scheduled for immediate enrichment,” and every backlogged CVE published before March 1, 2026 was moved to a “Not Scheduled” category. NIST also stopped routinely issuing its own severity score when the submitting CVE Numbering Authority had already provided one.

Modernization work has continued alongside the triage. On June 17, 2026, the NVD expanded its data feeds and APIs to carry Stakeholder-Specific Vulnerability Categorization data from CISA’s Authorized Data Publisher alongside existing severity scores, plus structured lists of affected software drawn from CVE records. The deployment touched approximately 95% of all vulnerabilities in the database, and NIST warned API users to expect larger payloads and elevated latency during the refresh.

What the Modernization Docket Could Shape

The notice positions the comment record as raw material for the NVD’s next phase: architecture, standards development, and data governance are all named as targets. For security teams whose tooling already depends on NVD enrichment, the questions on prioritization criteria, machine-readable data, and scoring standards are the ones most likely to surface in future NVD workflows — the same workflows April’s triage model reordered. NIST has also invited commenters to attach unpublished studies and empirical data, a signal the agency wants evidence, not just position statements.

The comment period closes October 13, 2026. Submissions received after that date may not be considered.

本地存档正文,来自 Unite.AI,内容版权归原作者/媒体所有,仅供个人阅读存档使用。