AI is changing the tempo of vulnerability discovery, but the systems defenders use to turn disclosures into patching decisions may not be keeping pace. BleepingComputer reports that vulnerability management is under growing strain as higher disclosure volume collides with processes built around slower validation, enrichment, prioritization and remediation cycles. The immediate pressure point is the National Vulnerability Database, or NVD. According to BleepingComputer, NIST said in April that updates to NVD operations reflected a scale problem: CVE volume had grown beyond what the current enrichment model was designed to handle. As part of that change, roughly 30,000 vulnerabilities published before March 1, 2026 were reclassified as “Not Scheduled,” the outlet reports. That does not mean the vulnerabilities disappeared. The issue is what happens when older entries remain without the structured context defenders expect from NVD. BleepingComputer’s account says selective processing and prioritization may be rational responses to volume, but they also create risk for enterprise security teams trying to determine which flaws apply to their environments and which need urgent remediation. The scale problem is supported in the item by figures from Action1’s 2026 Software Vulnerability Ratings Report. BleepingComputer says the report found disclosed vulnerabilities across the analyzed enterprise software categories rose 92% in 2025 compared with 2024. Critical and high-severity vulnerabilities each increased 103%, while vulnerabilities enabling remote code execution rose 128%, according to the same report. The operational concern is not only that a backlog exists. It is that prioritizing newer CVEs over older unprocessed entries may create an uneven signal for defenders. BleepingComputer argues that some vulnerabilities may already be known, confirmed, or discussed by vendors and researchers, while still lacking full NVD context. That context matters because enrichment is what turns a disclosure into a decision. Structured metadata, affected-platform information, severity scoring, configuration details and related fields help security teams decide whether a vulnerability applies to their estate and how quickly it should be fixed. Without that context, teams may either wait for better information or act from fragmented sources. The asymmetry is that attackers do not need standardized enrichment before moving. BleepingComputer notes that attackers can correlate vendor advisories, security research, patch releases, exploit information and public disclosures without waiting for NVD normalization. Defenders that have built workflows around NVD as a central normalized feed may therefore face delays at exactly the point when disclosure volume is rising. This is a developing story because the provided cluster contains only one source and because some of the key figures come through Action1’s report as cited by BleepingComputer. Still, the operational takeaway is clear enough for security leaders: vulnerability management is becoming less about consuming a single authoritative feed and more about correlating multiple intelligence sources quickly enough to support remediation. Who benefits: Teams with mature vulnerability intelligence pipelines benefit, especially if they can combine multiple sources and move from disclosure to remediation without waiting on one database. Automation that helps validate applicability and prioritize fixes also becomes more valuable. Who's exposed: Organizations that depend heavily on NVD enrichment as the trigger for action are more exposed to delays or blind spots. The risk is highest where patching decisions require normalized severity, affected-platform and configuration data before work begins.