Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST says CVE submissions rose 263% from 2020 to 2025, but that increase does not prove AI caused it—or that software is suddenly producing more flaws. The figures measure vulnerability reporting activity, not the number of newly created bugs or the tools used to find them. Here is what the evidence shows, what it does not, and why the distinction matters to security teams.

What the reported CVE increase actually measures

A CVE is an identifier and public record for a disclosed cybersecurity vulnerability. The CVE Program’s mission is to “Identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.” Records are published by participating CVE Numbering Authorities (CNAs). A CVE submission, a published CVE record, an NVD-enriched record, and a newly discovered flaw are related but different things.

NIST’s April 15, 2026 announcement said CVE submissions increased 263% between 2020 and 2025. It also reported that submissions in the first three months of 2026 were nearly one-third higher than in the same period of 2025. Those numbers indicate a substantial rise in submissions and associated processing workload; they do not say how many flaws were newly created, when each was discovered, or whether AI helped identify it. NIST’s announcement on NVD operations is the source for those submission figures.

The CVE Program’s metrics page displayed 70,729 published records for 2025 and 54,694 for 2026 in its snapshot accessed October 4, 2026. The 2026 number is a partial-year total, not a full-year result; the page says totals can be recalculated as record statuses change. These are published-record counts, not the submission counts in NIST’s announcement, so they should not be treated as interchangeable or compared as though they measure the same thing. The CVE Program’s live metrics page provides the record-count context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Tech Edvocate article published September 21, 2026, says 66,401 CVEs were registered “in the past year” and attributes the rise to AI vulnerability-discovery tools. The official materials cited here do not validate that figure as an annual published-record or submission total, and they do not establish AI as the cause of the broader increase. The number should therefore be read as that article’s claim, not as a confirmed official statistic.

Does AI create software vulnerabilities, or help find them?

AI-assisted analysis can be used to search code and systems for weaknesses, but finding a flaw is not the same as creating one. A tool might help surface a weakness that already exists in software; a higher volume of reports could also reflect changes in disclosure, submission, or processing activity. The reviewed official figures do not identify the discovery method behind submissions, so they cannot resolve how much AI contributed.

There is a separate question: when should a vulnerability associated with AI itself receive a CVE? The CVE Program’s February 18, 2025 guidance says a known vulnerable implementation may qualify when there is a secure way to use the functionality. Some risks that are inherent to models broadly may be better addressed through other initiatives rather than treated as a flaw in a particular implementation. The CVE Program’s guidance on AI-related vulnerabilities explains that distinction.

Why NIST changed its vulnerability-data workflow

NIST’s National Vulnerability Database (NVD) adds analysis and enrichment to CVE records. Faced with the increase in submissions, NIST announced on April 15, 2026, that it would prioritize records tied to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog, software used by the federal government, and critical software.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST said all submitted CVEs would still be added to the NVD, but records outside those priority groups might not receive immediate enrichment. In practice, a CVE can be publicly recorded while additional NVD analysis is pending. “Not immediately enriched” does not mean a record was rejected or that a vulnerability does not matter; it means users should not assume that every record receives the same depth or speed of analysis.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the rise means for security teams

More submissions can make it harder to review every new record at the same pace. Teams should prioritize based on their own exposure and risk rather than treating a raw count—or the presence or absence of immediate NVD enrichment—as a complete severity judgment.

  • Check the measure and date. Distinguish submissions from published CVE records and NVD-enriched records. For live metrics, note the date of the snapshot and whether a year is complete.
  • Match records to your environment. Identify whether affected products and versions are actually deployed, exposed, and relevant to business-critical systems.
  • Use risk context. Give particular attention to vulnerabilities listed in CISA’s KEV catalog and to issues affecting critical or federally used software, while still assessing other vulnerabilities against your own threat model.
  • Track status as well as identifiers. When enrichment is pending, use the published record as an initial signal and continue monitoring for updates from the relevant CNA, vendor, and NVD.
  • Keep remediation operational. A larger queue makes reliable asset inventories, ownership, patch or mitigation procedures, and clear escalation rules more important; a CVE count alone cannot tell a team what to fix first.

The evidence supports a real rise in CVE submissions and a change in NIST’s prioritization workflow. It does not establish that AI caused the increase, that the same number of new flaws were created, or that attackers have gained a measurable lead over defenders. AI-assisted discovery remains relevant, but the headline’s causal claim goes beyond what the cited official data can show.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
SaleBestseller No. 4

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.