NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.
- Sarah Gooding
The National Institute of Standards and Technology is asking the cybersecurity community how artificial intelligence should reshape the National Vulnerability Database, more than two years after the agency began publicly pointing to automation as a solution for its growing vulnerability processing problems.
The Request for Information seeks input on improving the NVD's "scalability, automation, interoperability, transparency, and utility." A separate NIST blog post accompanying the RFI disclosed that the agency has begun developing an AI-enabled tool called V-etalon.
The announcement arrives four months after NIST moved most CVEs outside routine enrichment, and less than three months after a federal audit found that the agency had no strategic plan for the NVD, no workable plan to clear its backlog, and no sustainable process for keeping pace with new submissions.
NIST is now seeking public comments to inform its "future strategic planning efforts." The agency is asking stakeholders to help shape a strategy after years of missed deadlines, abandoned proposals, shrinking enrichment commitments, and repeated assurances that automation was being explored.
NIST Has Not Released V-etalon
NIST offered one paragraph about V-etalon under the heading "Steps We've Already Taken":
We have already begun work on a tool, called V-etalon, that leverages AI technologies to aid in enriching vulnerability information. We hope that V-etalon will eventually provide a foundation for the evaluation of vulnerability information. We will be looking for feedback and collaboration opportunities once it’s available, all via GitHub (please stay tuned for an upcoming release and announcement).
The disclosure provides no release date, repository, documentation, architecture, evaluation results, or description of which enrichment fields the tool will address. NIST does not say whether V-etalon will generate CVSS scores, identify CWEs, build CPE applicability statements, validate data supplied by CVE Numbering Authorities, or perform some other function.
Even its intended role remains unclear. NIST says the tool will "aid in enriching vulnerability information," then describes it as a possible foundation for evaluating vulnerability information. Those are different jobs, and the agency does not explain how V-etalon would enter the NVD's production workflow or how human analysts would review its output.
The full RFI asks the public which vulnerability management tasks are suitable for AI, which should require human review, what safeguards are needed, and how AI-driven decisions can remain transparent and auditable. Those are foundational design questions for the tool NIST says it has already begun building.
Automation Has Been on the Roadmap Since 2024
NIST has been presenting technology and automation as the long-term answer to the NVD's capacity problems since the backlog first became visible.
In May 2024, while promising to clear the backlog by the end of that fiscal year, NIST said it was working on "technology and process updates" to support the automation of vulnerability management, security measurement, and compliance. The agency missed that deadline, and federal auditors later found that meeting it would have required NIST to process about 6,200 vulnerabilities per month, above both its historical output and its estimated maximum capacity.
In November 2024, after the backlog passed 20,000 CVEs, NIST said it was "developing new systems" to process data from Authorized Data Publishers more efficiently. NIST did subsequently deploy support for ingesting ADP data, including enrichment supplied by CISA. That change improved data ingestion and attribution, but it did not automate the NVD's core enrichment work.
By March 2025, NIST was "exploring the use of machine learning to automate certain processing tasks". It identified no tasks, tools, milestones, or delivery dates. At VulnCon the following month, NVD leaders described pilot tools for Linux kernel CVE enrichment and research into machine learning and AI-backed methods. NIST did not link to a public pilot or announce a production deployment.
In April 2026, NIST again cited "automated systems and workflow enhancements" as necessary for long-term sustainability. The announcement included no technical details or timeline. It accompanied the agency's decision to stop routinely enriching most CVEs.
V-etalon gives that recurring automation plan a name. The announcement still leaves the same central questions unanswered: what the system does, how well it works, when the public can inspect it, and when it will change NVD output.
NIST Is Enriching Fewer CVEs
The NVD already automates the easy part of its pipeline. According to the RFI, CVE records are ingested within approximately one hour of publication. NVD analysts then perform the enrichment that makes those records operationally useful, including assigning severity information and identifying affected product versions.
That second stage has been a perennial bottleneck for the NVD. In April, NIST abandoned its longstanding goal of analyzing every CVE. The agency now prioritizes CVEs in CISA's Known Exploited Vulnerabilities catalog, vulnerabilities affecting software used by the federal government, and vulnerabilities in software designated as critical under Executive Order 14028. Other CVEs can be placed in "Not Scheduled" status and considered later as resources allow.
NIST also stopped routinely producing an independent CVSS score when a CNA has supplied one, limited reanalysis of modified CVEs, and moved backlogged records published before March 1, 2026 into "Not Scheduled." NIST said CVE submissions had increased 263% between 2020 and 2025, while the nearly 42,000 CVEs it enriched in 2025 still failed to keep pace.
The August RFI describes demand for near-real-time enrichment at the same time the NVD is providing routine enrichment for a narrower share of the vulnerability stream. V-etalon is being presented as a possible bridge between those positions, but NIST has supplied no evidence yet that the tool can close that gap.
Not Scheduled CVEs Outnumber Active Enrichment Nearly 14 to 1
The NVD dashboard shows how that reduced enrichment scope is reflected in the current data. As of August 17, the database had received 53,115 new CVEs in 2026 and enriched 30,531. During August, it had received 6,092 new CVEs and enriched 2,246.
The status counts show a much larger body of records outside the active enrichment queue. NIST listed 42,353 CVEs as "Not Scheduled," compared with 2,426 "Awaiting Enrichment" and 623 "Undergoing Enrichment." The Not Scheduled category was nearly 14 times larger than the two active enrichment queues combined.
Those CVEs remain available through the NVD, but they are outside scheduled analysis unless they meet NIST's prioritization criteria or are selected for enrichment as resources allow.
The RFI Starts Where the Audit Ended
The Commerce Department Office of Inspector General's May audit found that NIST "does not have sustainable processes to manage NVD submissions" and would be unable to clear the backlog or prevent future processing delays without significant changes.
Auditors found that NIST had no strategic plan when they requested one. The backlog grew from about 13,000 vulnerabilities in June 2024 to more than 27,000 by the end of 2025. NIST and CISA also duplicated at least 21,000 enrichment activities between May 2024 and December 2025, in some cases using the same contractor. OIG estimated that the duplication wasted approximately $200,000.
The audit recommended that NIST create a strategic plan, establish a backlog management plan with milestones and a target date, reduce unnecessary severity scoring, improve external contribution paths for CPE data, coordinate with CISA, and develop a communication strategy. NIST agreed with all six recommendations and said it was developing an initial strategic plan.
The new RFI contains 30 questions across seven categories, spanning vulnerability dissemination, risk prioritization, remediation, standards, development processes, and a five-year vision for the NVD. It asks stakeholders which metrics should measure modernization success.
The RFI Reaches Beyond the NVD
The filing's scope is considerably broader than the database modernization described in its title. Its first six sections ask about the full vulnerability management lifecycle, information dissemination, risk prioritization, automated remediation, vulnerability standards, and development processes. The seventh is titled "Vision for the NVD."
Andrey Lukashenkov, a vulnerability intelligence expert, highlighted that split in his commentary on the filing:
The National Institute of Standards and Technology (NIST) opened a docket on modernizing the #NVD. Thirty questions across seven sections - and the NVD only really shows up in one of them.
The other six are an honest question about how you build #vulnerabilitymanagement now, filed as a database questionnaire.
The NVD is named in individual questions about interoperability and machine-readable data outside the final section. Much of the filing, however, asks about organizational processes and operating context that a public vulnerability database cannot supply.
Lukashenkov contends that the underlying vulnerability record ecosystem is already richer than it has ever been, with CVE records, CISA Vulnrichment, OSV, and GitHub Security Advisories each supplying parts of the information operators need:
The record layer is in better shape than it has ever been. #CVSS, #CWE, affected and unaffected versions and references now ship in the #CVE record itself. Cybersecurity and Infrastructure Security Agency #Vulnrichment layers more in after publication. #OSV and #GHSA carry the package, the affected range and the version that fixes it for open source. The parts all exist now. They just don't arrive joined up.
His larger point is that exposure and remediation decisions still depend on an organization's own inventory. An external database cannot determine whether a system is publicly exposed, or identify precisely which package version and source an operator needs to update. The RFI acknowledges this dependency when it asks whether discovery and asset inventory are prerequisites for automated remediation.
Lukashenkov also questioned how central AI needs to be to the exercise. "The filing leans hard on #AI - maybe harder than it needs to," he wrote. "Probably this is just a sign of the times."
CPE Remains the Hardest Problem
NIST also disclosed that it has begun updating the Common Platform Enumeration specification:
Additionally, NIST has kicked off work to update the Common Platform Enumeration (CPE) specifications, a mechanism for describing vulnerable products to better apply to hardware and to improve the specifications based on learning from over a decade of use. NIST held a workshop in June to share initial directions and gather feedback.
CPE data connects a vulnerability to affected products and versions, allowing security tools to determine whether a CVE applies to an environment. The OIG audit found that severity scoring and CPE applicability statements together consumed an estimated 80% of NVD enrichment time. It described CPE mapping as manual and time-consuming, particularly when products were absent from the CPE dictionary.
CISA stopped creating CPE applicability statements in December 2024, leaving NIST as the only federal provider while the NVD was already falling behind. That makes CPE one of the clearest tests for any AI enrichment system.
NIST's CPE 3.0 project page says the revision remains in early development, no specification text exists, and no technical changes are final. NIST has not said whether V-etalon will create or evaluate CPE applicability data, or how a new CPE specification will interact with the tool.
Another Plan Still Waiting for Deliverables
Comments on the RFI are due October 13, 2026 at 11:59 p.m. Eastern Time. NIST says the responses will guide strategic planning, tool development, architecture, standards, best practices, and data governance. The filing warns that relevant comments will be posted publicly without change or redaction.
By then, stakeholders will have supplied detailed answers about the future of a database that many of their products and compliance workflows still depend on. NIST has not said when it will release V-etalon, publish its evaluation criteria, complete an NVD strategic plan, or demonstrate that automation can restore enrichment at the scale the vulnerability ecosystem requires.
For more than two years, NIST's automation plans have remained largely in the future tense while the NVD's enrichment scope has contracted. V-etalon could become a public artifact showing how that changes. Until its code, benchmarks, and operating model are available, the announcement remains another promise that the automation is coming.
