What happened
On August 12, 2026, NIST published a Request for Information in the Federal Register (and companion Cybersecurity Insights blog post) seeking public input on modernizing the National Vulnerability Database (NVD) to address an 'evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data.' The RFI asks for stakeholder input on opportunities, challenges, and priorities for incorporating AI/automation into NVD workflows and vulnerability management data formats.
Why it matters
The NVD is the foundational US government repository for standards-based vulnerability data (CVE/CPE/CVSS) underpinning vulnerability management tooling worldwide, including AI-driven vulnerability scanners and SOAR platforms. Changes to its data model or AI-consumption formats would ripple through the entire vulnerability management ecosystem, security tooling vendors, and compliance frameworks that rely on NVD data.
Action needed
Security teams, tool vendors, and researchers should review the RFI and submit comments on how AI-enabled/machine-consumable vulnerability data should be structured; monitor for resulting NVD process or schema changes.