Rapid7 Policy Paper 'Modernizing Global Vulnerability Standards' Warns AI-Driven Vulnerability Discovery Is Outpacing CVE/CVSS/NVD Standards — Threadlinqs Intelligence
As of 2026-07-11, Rapid7 Policy Paper 'Modernizing Global Vulnerability Standards' Warns AI-Driven Vulnerability Discovery Is Outpacing CVE/CVSS/NVD Standards is a informational-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1214 · Severity: INFORMATIONAL · Status: MONITORING · Category: THREAT_INTEL
Rapid7 published a policy paper urging reform of CVE, CVSS, NVD, CISA KEV, and EPSS after presenting findings to a White House private-sector consultation in June 2026, arguing that production AI
On June 29, 2026, Rapid7 published 'Modernizing Global Vulnerability Standards,' authored by Corey Thomas (Chairman & CEO) and Sabeen Malik (VP, Global Government Affairs & Public Policy), and presented its findings to the White House during a private-sector consultation earlier in June 2026. The paper's central claim is that the legacy vulnerability-disclosure and scoring ecosystem — CVE identifiers, CVSS scoring, the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities (KEV) catalog, the Exploit Prediction Scoring System (EPSS), and the Vulnerabilities Equities Process — was designed for human-paced research and can no longer absorb AI-paced vulnerability discovery.
The paper cites Stanford HAI's AI Index 2026 finding that unguided AI agent solve rates on the Cybench cybersecurity benchmark rose from 15% in 2024 to 93% in 2025, and that CVE submissions grew 263% between 2020 and 2025 from human-driven discovery alone — before accounting for AI-assisted discovery. It notes that in April 2026, Anthropic, OpenAI, and Google DeepMind each announced production-grade AI systems capable of discovering, chaining, and in some cases remediating software vulnerabilities: Anthropic's 'Mythos Preview' model found high-severity vulnerabilities in every major operating system and web browser; OpenAI expanded its 'Daybreak' cybersecurity initiative with a full release of GPT-5.5-Cyber and launched 'Patch the Planet' with Trail of Bits to help open-source maintainers triage and repair vulnerabilities; and the Linux Foundation received $12.5M in grants from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI (managed via Alpha-Omega and OpenSSF) to help maintainers absorb the resulting influx of findings.
The paper's urgency is reinforced by two independent government-side signals cited in the surrounding coverage: (1) on April 15, 2026, NIST announced it could no longer keep pace with 'record growth' in CVE submissions and shifted NVD to a risk-based triage model — prioritizing enrichment only for CVEs in the CISA KEV catalog, CVEs affecting software used within the federal government, and CVEs for 'critical software' as defined by Executive Order 14028, while moving all backlogged pre-March-2026 CVEs to a 'Not Scheduled' category; and (2) a May 26, 2026 Department of Commerce Office of Inspector General report (OIG-26-020-I) found NVD severity scores matched independent evaluators only 12% of the time (i.e., wrong roughly 88% of the time), that the unprocessed backlog grew from ~13,000 entries in June 2024 to over 27,000 by end of 2025, and that in the 30 days before April 7, 2026 the NVD served roughly 300,000 unique users downloading an average of 22 terabytes of data per day — a scale mismatch the IG called a threat to 'the NVD's utility and public trust.' NIST was ordered to submit a corrective action plan addressing all six IG recommendations by July 31, 2026.
The paper's timing also follows a June 23, 2026 Five Eyes cyber security agencies joint statement warning that AI models capable of launching major cyberattacks able to overwhelm government and business defenses are 'months, not years' away, and that AI is shortening the time between vulnerability discovery and exploitation — a framing Rapid7 leverages to argue reform cannot wait for the next multi-year standards cycle.
Rapid7's recommended reforms: (1) formally recognize verified AI-demonstrated exploitability as a distinct evidentiary category in CVE/NVD records; (2) add chaining-risk metadata to vulnerability records so defenders can see when a low/medium-severity finding is part of a viable multi-step exploit chain; (3) require reachability guidance accompanying AI-discovered findings (i.e., whether the vulnerable code path is actually reachable/exploitable in a given deployment, not merely present); (4) update the Vulnerabilities Equities Process to account for AI-discovered zero-days; (5) direct new investment into CVE and N
Target sectors: government administration, technology, critical-infrastructure, open-source-ecosystem
Target regions: united states of america, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFORMATIONAL, threat intelligence, cybersecurity, T1596, T1592, T1587, T1588, T1585, T1190, T1195, T1203, T1068, T1211