Security

CVE Program turns to automation to handle AI-driven vulnerability surge

CISA and MITRE leaders say the global vulnerability database will scale despite unprecedented flood of AI-generated bug reports.

Omega Editorial· August 11, 2026· 3 min read

The global system that assigns unique identifiers to software vulnerabilities is confronting an unprecedented wave of AI-generated bug reports, but program leaders say they have a plan to manage the deluge without compromising the database that underpins the cybersecurity industry.

The Common Vulnerabilities and Exposures (CVE) Program will "find a way to scale," according to Lindsey Cerkovnik, branch chief for vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency (CISA), speaking at the Black Hat USA conference. "CVE is going to continue to flourish and improve, and I feel very positively about it."

Yet the scale of the challenge is staggering. GitHub, one of more than 530 CVE Numbering Authorities authorized to issue vulnerability identifiers, has published over 7,000 identifiers in 2026 alone — believed to be an annual record. CISA's vulnerability response team now handles between 360 and 400 cases simultaneously, a marked increase from previous years.

Why it matters

The CVE Program serves as the foundation for vulnerability management across the entire cybersecurity industry. If the system becomes overwhelmed or loses credibility, organizations worldwide would lose their primary method for tracking and prioritizing security patches. The current AI-driven surge represents the program's most severe stress test in its 27-year history, coming just over a year after a contract crisis nearly shut it down.

Automation as the answer to AI overload

CISA is exploring automated triage processes to help its limited staff focus on the most critical vulnerabilities. The agency recently granted OpenAI and Anthropic temporary CNA status, allowing these AI labs to assign CVE identifiers to vulnerabilities their models discover in certain software — a significant policy shift aimed at bringing frontier AI companies into the formal vulnerability coordination system.

The quality of AI-generated reports has improved since early 2026, when GitHub's Madison Ficorilli said the first four months were full of "AI slop." But that improvement creates its own problem: convincing but flawed reports now consume more time to evaluate. "It may be easier to just say, 'OK, this looks valid enough. I'm just going to fix it,'" Ficorilli noted.

Prioritization over patching everything

Cerkovnik emphasized that organizations cannot treat every vulnerability identically and must accept that some flaws may never warrant patching. "Not all vulnerabilities matter, and even vulnerabilities that matter don't all matter at the same level for you and your organization," she said. CISA has urged private organizations to follow guidance from its recent binding operational directive to federal agencies on vulnerability prioritization.

The agency is particularly concerned that the sheer volume of reports will overwhelm security teams and inadvertently create gaps in defenses. Security leaders need to make the case to executives "that not patching something, ever, is an option," Cerkovnik said.

Global coordination without fragmentation

Despite the emergence of parallel systems like the EU Vulnerability Database, program leaders said fragmentation is not a concern. The European system is built around CVE identifiers, and Nuno Rodrigues Carvalho from the European Union Agency for Cybersecurity said at Black Hat that "we don't see it as a duplication of effort whatsoever."

Still, not everyone shares the optimism. Katie Noble, a CVE Program board member who leads product security incident response for Intel, was blunt: "I don't think the CVE Program was designed to be able to manage [this] influx of vulnerabilities. I don't think it is capable of keeping up at this point."

These details were first reported by Cybersecurity Dive, based on panels at the Black Hat USA and DEF CON security conferences in Las Vegas.

#cve program#vulnerability management#ai security#cisa#automation

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

Security researchers exploit Zoom flaw using AI in under 20 prompts

The vulnerability allowed attackers to hijack devices during meetings through Zoom's annotation feature, requiring no victim interaction.

Via AI Watch · Aug 11, 2026
Security· 3 min read

AI Finds Zoom Screen-Sharing Flaw in Under 20 Prompts

Researchers used publicly available AI models to discover vulnerabilities that could enable silent device takeover during video calls.

Via WIRED · Aug 11, 2026
Security· 3 min read

Anthropic Embeds Watermarks in Claude to Track AI-Generated Text

The AI lab's new feature aims to make ghostwritten content detectable, though heavy editing can still defeat the system.

Via AI Watch · Aug 11, 2026