CVE Program turns to automation to handle AI-driven vulnerability surge
CISA and MITRE leaders say the global vulnerability database will scale despite unprecedented flood of AI-generated bug reports.
The global system that assigns unique identifiers to software vulnerabilities is confronting an unprecedented wave of AI-generated bug reports, but program leaders say they have a plan to manage the deluge without compromising the database that underpins the cybersecurity industry.
The Common Vulnerabilities and Exposures (CVE) Program will "find a way to scale," according to Lindsey Cerkovnik, branch chief for vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency (CISA), speaking at the Black Hat USA conference. "CVE is going to continue to flourish and improve, and I feel very positively about it."
Yet the scale of the challenge is staggering. GitHub, one of more than 530 CVE Numbering Authorities authorized to issue vulnerability identifiers, has published over 7,000 identifiers in 2026 alone — believed to be an annual record. CISA's vulnerability response team now handles between 360 and 400 cases simultaneously, a marked increase from previous years.
Why it matters
The CVE Program serves as the foundation for vulnerability management across the entire cybersecurity industry. If the system becomes overwhelmed or loses credibility, organizations worldwide would lose their primary method for tracking and prioritizing security patches. The current AI-driven surge represents the program's most severe stress test in its 27-year history, coming just over a year after a contract crisis nearly shut it down.
Automation as the answer to AI overload
CISA is exploring automated triage processes to help its limited staff focus on the most critical vulnerabilities. The agency recently granted OpenAI and Anthropic temporary CNA status, allowing these AI labs to assign CVE identifiers to vulnerabilities their models discover in certain software — a significant policy shift aimed at bringing frontier AI companies into the formal vulnerability coordination system.
The quality of AI-generated reports has improved since early 2026, when GitHub's Madison Ficorilli said the first four months were full of "AI slop." But that improvement creates its own problem: convincing but flawed reports now consume more time to evaluate. "It may be easier to just say, 'OK, this looks valid enough. I'm just going to fix it,'" Ficorilli noted.
Prioritization over patching everything
Cerkovnik emphasized that organizations cannot treat every vulnerability identically and must accept that some flaws may never warrant patching. "Not all vulnerabilities matter, and even vulnerabilities that matter don't all matter at the same level for you and your organization," she said. CISA has urged private organizations to follow guidance from its recent binding operational directive to federal agencies on vulnerability prioritization.
The agency is particularly concerned that the sheer volume of reports will overwhelm security teams and inadvertently create gaps in defenses. Security leaders need to make the case to executives "that not patching something, ever, is an option," Cerkovnik said.
Global coordination without fragmentation
Despite the emergence of parallel systems like the EU Vulnerability Database, program leaders said fragmentation is not a concern. The European system is built around CVE identifiers, and Nuno Rodrigues Carvalho from the European Union Agency for Cybersecurity said at Black Hat that "we don't see it as a duplication of effort whatsoever."
Still, not everyone shares the optimism. Katie Noble, a CVE Program board member who leads product security incident response for Intel, was blunt: "I don't think the CVE Program was designed to be able to manage [this] influx of vulnerabilities. I don't think it is capable of keeping up at this point."
These details were first reported by Cybersecurity Dive, based on panels at the Black Hat USA and DEF CON security conferences in Las Vegas.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call