AI-driven vulnerability discovery outpaces traditional enrichment and remediation

The article discusses how AI is accelerating vulnerability discovery, but the rest of the vulnerability management ecosystem is struggling to keep up. NIST has reclassified roughly 30,000 older CVEs as "Not Scheduled," and Action1's report shows a 92% increase in disclosed vulnerabilities in 2025. This creates an information asymmetry where security teams may lack full context for older flaws while attackers can correlate vendor advisories without waiting for enrichment.
The scale of the problem is stark. Action1's report documents a 92% surge in disclosed vulnerabilities across enterprise software in 2025, with critical and high-severity flaws each rising 103% and remote code execution vulnerabilities climbing 128%. NIST's decision to mark roughly 30,000 pre-March 2026 CVEs as "Not Scheduled" reflects an enrichment pipeline strained beyond its original design capacity.
The consequences ripple through defender workflows. Without complete CPE data and affected-platform metadata, security teams face false positives and must either delay action or proceed on fragmented information. Meanwhile, attackers correlate vendor advisories, patch releases, and public disclosures directly, bypassing the enrichment bottleneck entirely.
The widening gap between vulnerability discovery and enrichment could leave organizations—particularly smaller enterprises without dedicated threat intelligence teams—making remediation decisions with incomplete context. Delayed or missing NVD