At the Cyber-AI expo, Florian Wininger, CTO and co-founder of Cyberwatch, provided an overview and shared his vision for the evolution of vulnerability management in the coming years. In 2025, no fewer than 48,000 CVEs were published, averaging 130 per day. Faced with this explosion, an increasing number of them are not being enriched in time, making rapid remediation impossible. AI is set to become essential for identifying, enriching, and prioritizing risks, as well as for automating remediation.
Vulnerabilities on the rise: the end of centralization
Historically, vulnerability management relied on a central player: the National Vulnerability Database (NVD), managed by the National Institute of Standards and Technology (NIST). Its role was to catalog CVEs, assign them a severity score (CVSS), and link them to the relevant products (using CPE, or Common Platform Enumeration, identifiers).
However, with the explosion in the number of vulnerabilities, the NVD can no longer keep up, resulting in publication delays, missing criticality scores, and a lack of information on affected products. During its last quarterly meeting, held in January 2026, NIST officials admitted they were fighting "a losing battle" and indicated their intention to shift toward a model where enrichment would be entrusted to CVE Numbering Authorities (CNAs).
CVE data enrichment: multiple sources
To help catalog and enrich information related to vulnerabilities, an entire ecosystem has gradually taken shape.
CNAs (CVE Numbering Authorities)
There are currently nearly 490 organizations authorized to document CVEs, including about ten at the "root" level, which have full authority to issue CVE numbers.
Note: since November 2025, ENISA, the European Union Agency for Cybersecurity, has been recognized as a root authority. In accordance with Article 12 of the NIS2 directive, Europe finally has its own database, called EUVD (European Union Vulnerability Database).
ADPs (Authorized Data Publishers)
When a CNA publishes a CVE, it reports the existence of a flaw but does not always provide the metadata essential for prioritization, such as the CVSS score or the CPE (identifier of the affected product). It is the role of ADPs (Authorized Data Publishers) to complete this information after the fact. Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is virtually the only ADP operating at scale.
European and national CERTs
European and national CERTs play an essential role in qualifying and triggering alerts for the most critical vulnerabilities. However, no single CERT covers the entire technological spectrum. For example:
- CERT-FR is particularly relevant for tools widely used in France, such as the open-source solution GLPI, but less consistently so for technologies like SAP or AIX;
- The Belgian CERT recently issued highly responsive alerts regarding emerging products like Moltbot or OpenClaw.
The open-source initiative Vulnrichment
To collectively enrich CVE data on a global scale, the open-source project Vulnrichment (a portmanteau of Vulnerability + Enrichment) was also launched on GitHub, featuring around a dozen active contributors, including Cyberwatch.
AI for automated CVE enrichment
To maintain broad-spectrum monitoring and accelerate the identification of new CVEs, Cyberwatch leverages the complementary nature of all these public sources: NVD, CNA, ADP, CERT, open-source contributions, and more.
Beyond monitoring vulnerabilities and their criticality levels, one of the major challenges is associating the correct CPEs with each CVE. In other words, precisely identifying the affected products and versions. Without this information, it is impossible to detect whether a vulnerability affects a given information system.
However, in 2025, a significant portion of CVEs did not receive this enrichment in a timely manner—sometimes for several days, and in some cases, never at all.
This is where artificial intelligence comes into play.
Faced with the multitude of CVE information sources, Cyberwatch has developed an AI-driven automated enrichment model that allows us to:
- Automatically identify the CPEs associated with published CVEs;
- Reconcile product and vendor names with CPE nomenclature;
- Process vulnerabilities on an hourly basis, without waiting for NVD updates.
The result: out of the 48,000 vulnerabilities in 2025, 13,000 were automatically enriched with a relatively low false-positive rate. The AI does not create the data, but it makes it actionable in real time, whereas waiting for human updates would take days or even weeks.
LLM-assisted CVE identification, prioritization, and remediation
Furthermore, Cyberwatch has integrated an MCP (Model Context Protocol) server into its vulnerability management platform. This allows users to interact with our platform directly from an LLM client (Claude, Copilot, ChatGPT, etc.) using natural language.
In practical terms, users can ask questions such as "What are the latest critical vulnerabilities for my Fortinet equipment?" and get real-time results:
- A list of recent CVEs concerning Fortinet assets;
- Identification of affected machines in your infrastructure (e.g., 6 FortiOS assets, 3 FortiAnalyzer, 3 FortiManager, 1 FortiWeb);
- The criticality level of each vulnerability;
- A proposed remediation plan.
The advantage of this approach over an LLM searching the web is that Cyberwatch queries its own database in real time, returning vulnerabilities published within the last few hours without the risk of a multi-week lag.
It is even possible to go further with autonomous AI agents capable of summarizing new vulnerabilities daily, identifying priority actions, and executing them automatically without human intervention. This approach could well revolutionize CVE detection, prioritization, and remediation workflows in the coming years.
Want to learn more? Get in touch with our team.
