After the Flood: Moving Beyond the U.S. Vulnerabilities Equities Process
Most governments conduct offensive cyber operations to keep themselves safe from international threats, steal secrets, or disrupt adversaries. The United States government was one of the earliest and most prolific users of such cyber capabilities, in part by discovering and exploiting zero-day vulnerabilities—flaws not yet known to those who made the software, and for which patches did not exist.
Some of these flaws were so dangerous, however, that the government’s main hackers at the National Security Agency (NSA) wanted to disclose them to the associated software vendor. In order to decide which vulnerabilities fell into this category, the NSA developed a vulnerabilities equities process (VEP) to determine which exploits the government should disclose to software vendors and which to retain for offensive cyber operations.
As cybersecurity became more existential for the United States, the White House took more control over this process in 2014, primarily to ensure a broader array of perspectives participated in the decision-making process about which vulnerabilities were too dangerous to retain. The VEP served the nation, and indeed everyone online, well.
Today, however, the VEP is no longer a good match for its original public-policy purpose: a high-level review of a relatively small number of vulnerabilities to balance offense and defensive equities.
What has changed in just 12 years? The short answer is artificial intelligence (AI). AI’s pace of discovery means that vulnerabilities are no longer found in ones and twos but in the hundreds. Furthermore, anyone with access to relatively common AI tools can find those vulnerabilities.
This article’s co-authors have strongly supported the VEP, having overseen its reform (Daniel) and as one of its earliest scholars (Healey). But it is time to reform, and possibly put on hold, the VEP. The VEP is resource intensive to operate, and given limited federal resources, those should be reallocated to higher-priority cybersecurity missions. However, the VEP should not be killed off entirely, as it may still further serve the American public.
Purpose of the VEP and Related Programs
Exploitation of vulnerabilities is one of the two major methods malicious actors use to gain access to networks (the other being social engineering).
At the same time, not all known vulnerabilities are exploited. In fact, historically, fewer than 6 percent of known vulnerabilities were ever used in malicious activity. As the number of vulnerabilities grew beyond defenders’ ability to patch all of them, the cybersecurity industry had to develop vulnerability management programs so that defenders would know which flaws need patching and in what order.
The needs of vulnerability management programs in turn drove the development of an entire ecosystem to catalog, reduce, and prioritize vulnerabilities.
- The common vulnerabilities and exposures process aims to catalog all known vulnerabilities, using a common framework and nomenclature.
- To reduce the prevalence and severity of vulnerabilities, defenders have developed resources such as the Open Web Application Security Project’s top 10 and the Common Weakness Enumeration’s top 25 lists, which track the top application security risks and top software weaknesses, respectively.
- Programs include the common vulnerability scoring system (which scores each vulnerability for criticality), the known exploited vulnerability catalog (KEV), which lists the vulnerabilities actually used in attacks, and the exploit prediction scoring system (EPSS), which tracks what vulnerabilities are most likely to be exploited. Together, the processes enable defenders to prioritize vulnerabilities for remediation.
Even as the U.S. government partners with industry to patch vulnerabilities, it also conducts intelligence programs, offensive cyber operations, and law enforcement activities that rely on exploiting vulnerabilities to succeed. The U.S. government would be derelict if it did not conduct such activities. Therefore, the government developed programs to find vulnerabilities for these purposes.
The government’s need for both defensive and offensive cybersecurity capabilities creates tension. When looking for vulnerabilities for offensive cyber operations, the U.S. government also finds vulnerabilities that are either too dangerous, widespread, or not useful to keep secret. The public-policy problem is determining what category a given vulnerability falls into.
The earliest government program for offensive vulnerabilities was the Information Operations Technology Center, which the NSA established in the mid-1990s to create a common “toolbox” of capabilities across the NSA and the military services. At the time, the U.S. government considered itself so far advanced compared to adversaries that it believed it would find vulnerabilities that no one else would. Such bugs would require computational power or expertise that would be available to “NOBUS,” no one but us.
However, when other nations invested in cyber capabilities and a robust cyber researcher community emerged, the NOBUS belief became harder to sustain; the U.S. government could no longer assume it would have exclusive knowledge about a given vulnerability even for a limited time. Further, businesses and governments increasingly used the same limited number of technology stacks, and government vulnerability researchers found themselves targeting systems on which not just the U.S. government but also critical infrastructure depended. Given these conditions, the “equities” of defenders needed to be included in a decision about what to do with vulnerabilities that the U.S. government discovered.
To balance these competing equities, the U.S. developed a formal process known as the VEP. Specifically, the VEP was developed (in 2010 originally, with updates in 2014 and 2017) to handle a key decision: When should the U.S. government retain a vulnerability for its own espionage missions, and when should it disclose the vulnerability to the vendor?
After the Snowden revelations and the 2013 Heartbleed vulnerability (that was initially falsely reported to have been actively exploited by NSA), the White House elevated the VEP to ensure a wider, interagency group reviewed those offensive and defensive equities, rather than just the NSA. The White House adopted the principle that disclosure was the default position and that the decision to retain a vulnerability would be revisited on a regular basis.
The White House’s decision criteria included a range of factors, including whether U.S. infrastructure used the vulnerable system, what harm an adversary could cause, whether the U.S. would know if someone else had access, whether the system could be patched or mitigated, and how likely it is that someone else could discover the vulnerability. There was, for example, no reason for the government to disclose the vulnerability if it was used only to protect Chinese infrastructure or if the system “has no inherent security features by design.”
The VEP showed the United States could be a responsible cyber power, defaulting to disclose vulnerabilities to prefer the defense.
From a Trickle to a Flood
The VEP no longer fits its original public-policy purpose.
The NOBUS mindset driving the VEP was probably an antiquated concept several years ago, but as AI has democratized the once-rare expertise and computational power, it is now definitely dead: Threat actors no longer need scores of PhDs and “four acres of Cray computers in the basement” to make exquisite discoveries. There are too many vulnerabilities, too many of which are critical, discovered by too many threat actors.
The trend is already well underway:
- Finding bugs in cryptography libraries normally requires months of painstaking manual analysis by elite security researchers. But a research team at OpenSSL recently used AI to discover 12 zero-day vulnerabilities.
- Palo Alto Networks discovered over 14,000 confirmed vulnerabilities across nearly 4,000 3,915 open-source projects in just two months. Not only were 99.4 percent of them previously unreported zero-days, but nearly 40 percent were rated high or critical.
- Trend Micro’s Zero Day Initiative reported a 490 percent year-over-year increase in monthly vulnerability submissions, from 287 in April 2025 to 990 in March 2026 and another 1,691 in April.
- Google had 429 vulnerabilities in a recent update, 100 of which are high or critical severity. A decade ago, Microsoft typically patched 50 to 60 vulnerabilities per month; in July 2026, this surged to 570, nearly triple the previous record.
- One senior cybersecurity executive noted (in a discussion under the Chatham House rule) that after the company patched vulnerabilities discovered through AI tools, subsequent AI-driven reviews found fewer bugs. A given set of code has a finite number of flaws.
The VEP cannot and should not be expected to handle the volumes of vulnerabilities government researchers can now find using AI tools. The review process is onerous, with writeups running to hundreds of pages of technical analysis. The NSA has had to dedicate several full-time employees to manage the program, and reviews require technical experts from across the interagency to invest considerable time. Moreover, researchers outside government will also find most bugs nearly simultaneously, rendering the whole process moot.
Moving Beyond VEP
The VEP no longer serves the American people, at least as originally structured. The U.S. government cannot assume it will have exclusive access to a given vulnerability even for a limited time. The process cannot scale to review the flood of potential vulnerabilities the government discovers in a timely manner. As cybersecurity resources shrink inside the federal government, the VEP draws people away from other activities. Combined, these factors demonstrate that the current VEP no longer passes a cost-benefit test.
While a flood of AI-discovered bugs will likely happen, other outcomes remain unclear. Accordingly, we do not recommend eliminating VEP entirely, at least not yet. It is more important to keep government options open for maximum flexibility, with changes to meet the needed public-policy priorities of an AI age.
We envision several possible options for the Office of the National Cyber Director at the White House. The first three options, which we find unconvincing, look at how a revamped VEP might continue to be useful.
Cataloging U.S. Exploited Vulnerabilities
Instead of a VEP to approve vulnerability retention, a reformed process might catalog the vulnerabilities the U.S. uses in offensive operations.
Such a list would mirror the existing KEV list, which is what adversaries use, not the United States. It would be a close throwback to the NSA’s Information Operations Technology Center in the 1990s, though it would be less of a toolbox and more of a catalog of vulnerabilities currently exploited. A common catalog might impose a lower administrative burden than the current VEP but still provide some insights. For example, it might reveal vulnerabilities the U.S. government should watch for adversarial use; if the government sees such exploitation, having it cataloged and analyzed already would make rapid disclosure and mitigation easier. However, a probably fatal drawback is that any list of exploited vulnerabilities would need exceptionally high classification because anyone discovering the entire list might jeopardize all U.S. operations, unless the turnover of vulnerabilities is very frequent.
Tracking Vulnerabilities in AI
Another option is for the VEP to focus on truly exceptional vulnerabilities—those in AI itself. The VEP should not use any exploits AI labs have submitted to the government, as requested in President Trump’s Executive Order 14409, or else the labs will cease cooperation. However, Chinese open-source models may have vulnerabilities that the U.S. intelligence community might come across (some of those models might be used in U.S. and allied critical infrastructure).
The VEP is not designed to move as fast as AI, and it will not ever be. The chances of events overtaking it are very high.
Shifting From Vulnerabilities to Exploits
When vulnerabilities are plentiful, other factors—such as advanced exploitation development and techniques—may become substantially rarer and more important. A revamped VEP might review the most powerful and easiest to combine exploits, or new and risky exploitation techniques. At the moment, however, this concept remains speculative, and it will take time to determine if it is accurate.
Reforming the VEP
Perhaps AI is not just the problem but the solution? An AI-driven approach might substantially reduce the administrative burden, allowing it to succeed at speed and scale. But this just fixes the solution, not the problem. The whole idea of being able to “retain” vulnerabilities is going to be made obsolete, because they won’t stay secret.
VEP Timeout
The White House’s best option is to formally put the VEP on hiatus until the AI revolution’s full impact is clearer.
Rob Joyce, who oversaw and strengthened the VEP process in the first Trump administration, has argued convincingly that AI-discovered vulnerabilities will likely cause a great cleansing forest fire. In the short to medium term, defenders will be overwhelmed by countless vulnerabilities and attacks exploiting them. At some point, however, that inferno should die out, as few unpatched vulnerabilities are left that can have such an impact.
In that post-conflagration era, vulnerabilities would again become scarce, creating a far harsher environment for offensive teams. In such an environment, the VEP might once again have utility in assessing whether a vulnerability is too dangerous to keep secret. In fact, in such conditions, a VEP becomes even more valuable. Because creating new processes is much harder than restarting existing ones, pausing the existing VEP is therefore far preferable to killing it entirely.
A similar logic applies to another of the vulnerability-related projects, that of prioritization to drive decisions of which vulnerabilities to fix first. We have both just returned from the Black Hat and DEF CON security conventions, where we frequently heard comments that there would be so many vulnerabilities and that programs such as the KEV are obsolete.
We disagree, at least for now, for two reasons.
First, even though the total number of vulnerabilities will be a flood, possibly only a small number actually matter. Historically, adversaries exploited only about 5 to 6 percent of vulnerabilities. In 2025, even as far more vulnerabilities were discovered, the percentage of those actually exploited dropped, possibly to as low as 1 percent. Why? Probably because the bad guys didn’t need more exploits to achieve their goals. What they had worked just fine.
Second, because defenders can’t patch every vulnerability, they must choose which vulnerabilities to patch, which to mitigate, and which to leave alone and accept the risk. Accordingly, KEV will remain critical, alongside other prioritization programs, especially the EPSSA, so defenders have insight into what they must patch immediately and what can wait. Cyber defenders will need to keep an eye on the vulnerability exploitation rate and how quickly it increases above historical levels.
Calling Time Out
As vulnerability discovery, exploitation, and management transform into a fully industrialized and commoditized process, government policies and processes will need to adapt. Government agencies often keep programs unchanged long after their original purpose has disappeared.
In the case of the VEP, the conditions that made it necessary have changed dramatically. The program should change with it.
