Traditional vulnerability management and patching are struggling to cope with a growing flood of Common Vulnerabilities and Exposures (CVEs), according to security experts. Drew Vanover, principal security strategist at Horizon3, noted that Microsoft's latest patch cycle included over 500 fixes, which he called 'incomprehensible' for organisations to vet and deploy safely.
The US National Institute of Standards and Technology's National Vulnerability Database has been backlogged for years, and in April it effectively declared 'CVE bankruptcy'. A US Department of Commerce report in May criticised the NVD's management and suggested it stop assigning CVSS scores, which it described as highly subjective.
AI is expected to worsen the problem, with frontier LLMs already surfacing zero-days at scale and accelerating exploit development. In response, Gartner's CTEM framework—scoping, discovery, prioritisation, validation, and mobilisation—aims to focus on vulnerabilities that pose real business risk.
Horizon3's NodeZero automates penetration testing to identify exploitable paths and provides evidence for defenders. Vanover said the system uses a deterministic machine learning expert system rather than a general LLM, and that it can prove exploitation by actually doing it.