AI-Generated Fake Vulnerabilities Flood CVE Database as NIST Backlog Spirals
Key Takeaways
- ▸Six fake SQLite CVEs featured zero-day-like sophistication: references to non-existent functions, misattributed source code lines, and proof-of-concept code that executed flawlessly without triggering any actual vulnerabilities
- ▸NIST's backlog has grown 59% in 12 months, with a May 2026 Inspector General report blaming federal 'lack of strategic planning and decisive action' and wasted contractor funding
- ▸The CVE pipeline currently has no mandatory verification step—no proof-of-concept requirement, no independent reproduction mandate—allowing plausible fake advisories to reach production databases used by every major technology company
Summary
Security researchers at JFrog have exposed a critical breach of the CVE database: AI-generated fake vulnerabilities are being submitted to the National Vulnerability Database, with the specific AI system behind the campaign remaining unidentified. The researchers discovered 55 CVEs containing fabricated security flaws, including six fake SQLite vulnerabilities with CVSS severity scores ranging from 7.5 to 9.8 that referenced non-existent functions and misattributed source code. This attack exploits a catastrophic vulnerability in the pipeline: NIST's backlog has now exceeded 27,000 unprocessed CVEs (up from 17,000 in late 2024), crippling the agency's ability to manually review submissions. The database lacks any mandatory proof-of-concept requirements or independent vulnerability reproduction, relying instead on an honor system never designed to withstand AI-assisted fraud.
- A single attack batch contained 55 total fake CVEs (6 SQLite, ~49 targeting libraw and ESP32-audioI2S), with only one containing a real bug wrapped in fraudulent metadata
Editorial Opinion
The pollution of the CVE database with AI-generated fakes marks an inflection point in AI's impact on critical infrastructure. What started as AI-generated 'slop' in marketing has metastasized into a direct threat to the trust layer of software supply chain security. NIST's failure to keep pace isn't just a bureaucratic stumble—it's a public safety issue. The federal government must either mandate reproducibility requirements across the entire pipeline or accept a future where every CVE is treated as potentially fraudulent.



