What Happened
AI-assisted research is accelerating vulnerability discovery faster than the infrastructure defenders rely on to enrich, prioritize, and remediate those flaws can keep pace. A new analysis lays out the scale of the gap: disclosed vulnerabilities rose 92% in 2025 compared to the year before, with critical- and high-severity flaws each up 103%, remote code execution vulnerabilities up 128%, and enterprise application exploitation up 800% over the last year.
Compounding the volume problem, NIST reclassified roughly 30,000 vulnerabilities published before March 1, 2026, as "Not Scheduled" for enrichment — meaning a large slice of the historical CVE catalog now carries incomplete metadata that security teams depend on for prioritization.
The Core Problem: Discovery Has Outrun Enrichment
The bottleneck used to be finding vulnerabilities in the first place. AI-assisted research tooling has flipped that constraint: flaws are now surfacing faster than the enrichment pipeline (NVD scoring, vendor advisories, threat-intel correlation) can process them. That creates three compounding issues for defenders:
- Information asymmetry — when NVD enrichment lags, defenders are missing context attackers don't need to wait for. Exploitation doesn't pause for a CVSS score to get published.
- False prioritization — teams that focus only on freshly enriched CVEs risk leaving a growing backlog of older, unprocessed vulnerabilities unaddressed, simply because the data needed to rank them isn't there yet.
- Operational complexity — instead of relying on a single authoritative baseline, security teams increasingly have to correlate multiple intelligence sources (vendor advisories, threat intel platforms, NVD, CISA KEV) just to get a complete picture of exposure.
What's Recommended
The analysis points to three practical adjustments for vulnerability management programs:
- Combine intelligence sources — don't rely on NVD alone; correlate vendor advisories, threat intelligence platforms, and CISA's KEV catalog.
- Correlate with real-time endpoint data — vulnerability data is only actionable when matched against what's actually running in your environment.
- Integrate assessment with automated remediation — close the gap between "we know about it" and "it's patched" by wiring vulnerability data directly into remediation workflows rather than treating triage and patching as separate manual steps.
Vulnerability management vendor Action1 is cited as an example of this integrated approach, combining data from VulnCheck, NIST NVD, CISA's KEV Catalog, and Microsoft MSRC with live endpoint intelligence.
Why This Matters
This isn't an isolated observation — it echoes a pattern showing up across the industry this year, from Google's M-Trends findings on shrinking time-to-exploit windows to Microsoft's warnings about AI-discovered flaws increasing patch cadence. The throughline: the old assumption that disclosure-to-patch has a comfortable buffer no longer holds. Organizations that still treat vulnerability management as a periodic, manually-triaged process are the ones most exposed as AI-assisted discovery keeps compressing that window.