NIST NVD backlog and Claude Mythos reshape vulnerability defense

NIST says it will no longer enrich most vulnerabilities in the National Vulnerability Database because the backlog has grown too large. At the same time, the Cloud Security Alliance and the U.K.’s AI Security Institute say Anthropic’s Claude Mythos Preview can autonomously find and exploit vulnerabilities at a level that changes attacker economics.

NIST NVD backlog and Claude Mythos reshape vulnerability defense

NIST has formally said it can no longer enrich the majority of vulnerabilities flowing into the National Vulnerability Database, or NVD. The announcement, made on 14 April 2026, lands at the same time as a separate warning from the Cloud Security Alliance about Anthropic’s Claude Mythos Preview, which the group says marks a step change in autonomous vulnerability discovery.

Taken together, the two developments point to the same problem from opposite directions. Defenders are getting less coverage from the central database many security programs rely on, while attackers are gaining tools that can find and weaponize flaws faster than human teams can respond.

⚡ New to this?

This story is about two shifts happening at once. NIST’s NVD, or National Vulnerability Database, is the public catalog many security tools use to score and prioritize software flaws, but it can no longer keep up with the volume. At the same time, new AI tools appear able to find and exploit vulnerabilities much faster, which makes old patching workflows less reliable.

🦞 OpenClaw angle

If your automation or agent stack depends on CVE feeds, treat NVD as one signal, not the source of truth. Add CISA KEV, vendor advisories, and threat intel into your triage pipeline, and make sure your agent decides based on asset criticality and exposure, not just a CVSS score. For self-hosted agents that touch sensitive data, enforce data-layer controls: encrypt data with keys you control, log every access, and require authorization at the file or record level before an agent can read or send anything.

NIST said CVE submissions grew 263% between 2020 and 2025. In 2025 alone, NIST enriched almost 42,000 CVEs, a 45% increase year over year, but the backlog still climbed above 30,000 unanalyzed entries. Going forward, NVD will focus on three narrow categories: vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog, software used by the U.S. federal government, and a loosely defined group of “critical software.” Everything else will be marked “not scheduled,” with no severity score or analysis for scanners to use.

Dustin Childs, who leads threat awareness at Trend Micro’s Zero Day Initiative, told CSO Online that NIST has “publicly stated, ‘We are never going to get through this backlog.’” The Forum of Incident Response and Security Teams expects 59,427 CVEs in 2026, up from just over 48,000 in 2025, with some modeled scenarios above 100,000.

The quality of the data is also an issue. Dragos’s 2026 OT/ICS Year in Review said 15% of CISA and NVD CVEs had incorrect CVSS scores in 2025, and 64% of those corrections increased severity because vendors had understated the risk. Dragos also found that 25% of public advisories included no patch or mitigation guidance.

The Claude Mythos Preview story is moving in the opposite direction. The Cloud Security Alliance briefing was signed by former CISA Director Jen Easterly, Bruce Schneier, Chris Inglis, Phil Venables, and other senior security figures. It says Mythos represents “a step change” in AI-driven vulnerability discovery and that “the window between discovery and weaponization has collapsed to hours.”

The U.K.’s AI Security Institute independently evaluated the system and reported that it autonomously found thousands of zero-days, generated working exploits without human guidance, and completed a 32-step corporate network attack simulation from reconnaissance through takeover. The institute said the simulation had previously taken a skilled human red teamer about 20 hours.

The AISI report also said Mythos found and exploited a 17-year-old remote code execution flaw in FreeBSD’s NFS server in about four hours. CrowdStrike’s 2026 Global Threat Report adds more context, saying zero-day exploits rose 42% year over year and AI-enabled adversary attacks rose 89%.

The practical effect for security teams is a widening blind spot. Many organizations still depend on NVD enrichment and CVSS scores to decide what to patch first, but the source of that prioritization is now incomplete for most new vulnerabilities.

That matters for compliance as well as operations. The source article cites SEC cyber disclosure rules, CMMC and DFARS for federal contractors, and HIPAA risk analysis requirements for healthcare organizations. It argues that these frameworks make it hard to claim a risk-based prioritization process if the core risk signal is missing.

The article argues that more scanners and more tickets will not solve the problem on their own. Instead, it says organizations need controls at the data layer, such as attribute-based access control, encryption with customer-managed keys, tamper-evident logging, and zero-trust access for humans, services, and AI agents.

It points to Log4Shell as evidence that hardened data-layer architecture can reduce the impact of major vulnerabilities. According to the source, organizations with that design treated the incident more like a CVSS 4 event than a CVSS 10 one. The article closes by saying the next major flaw may not come with a CVE number attached, which makes architecture more important than any single vulnerability score.

Source: Kiteworks ↗

More from Security News