Cybersecurity teams are being urged to rethink how they manage software vulnerabilities as AI compresses the time between a flaw being disclosed and it being exploited.
The traditional model has changed little for years: scan software, identify CVEs, assign severity scores, prioritize findings and send them to developers. The New Stack analysis argues that approach never perfectly reflected risk, and AI has made its limits impossible to ignore.
The amount of software being produced is expanding rapidly, vulnerability discovery is accelerating, and the time required to develop exploits is shrinking. AI-enabled attacks can also chain vulnerabilities together in ways that are difficult to anticipate manually. The result is a widening gap between the vulnerabilities teams can identify and the ones they can meaningfully investigate and remediate.
The article argues the question should change from "How many CVEs do we have?" to "Which vulnerabilities create meaningful risk in our environment?" A CVE confirms a vulnerability exists, but not how likely it is to be exploited against a particular organization. CVSS scores describe technical severity and potential impact, but not whether an exploit exists, is being used in the wild, or whether the vulnerable component is exposed in a given environment.
Two organizations can carry the same CVE and face very different risk. One may have the component behind multiple layers of protection; another may run it in an internet-facing production application. As the article puts it: "The CVE is identical. The risk is not."
Programs built around static severity scores can produce misleading progress. The piece calls this "CVE theater": measuring activity rather than meaningful risk reduction.
AI is changing the economics of exploitation on both sides. More code means more exposure even if vulnerability density declines, and much modern software depends on open-source components. Attackers can automate tasks that previously required manual effort. The combination of more vulnerabilities and a collapsing time-to-exploit window creates a fundamentally different security environment.