AI-Driven Vulnerability Surge Threatens Global CVE System, Posing Existential Cybersecurity Risk for Banks
The MITRE-operated Common Vulnerabilities and Exposures (CVE) program assigns standardized identifiers to software flaws worldwide, while NIST adds severity ratings and product information through the National Vulnerability Database (NVD). Banks rely on this common language to prioritize patches, operate cybersecurity tools and meet regulatory requirements. A CISA contract covering CVE-related work worth about $57.8 million underscores the system's heavy dependence on a single source of government funding.
On April 15, 2026, NIST said CVE submissions had surged 263% from 2020 to 2025. Although it enriched nearly 42,000 records in 2025, 45% more than the previous annual high, NIST still shifted to prioritizing vulnerabilities that were being actively exploited or affected critical software. On May 13, 32 members of the U.S. House of Representatives requested a White House briefing within 30 days and a written response within 45 days after AI models discovered thousands of high-risk zero-day vulnerabilities.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.