AI is generating fake CVEs - and they're making it into real vulnerability databases

Security & Trust il y a 37 min3Ajouter aux favoris

AI is generating fake CVEs - and they're making it into real vulnerability databases
Illustration : Léa Fontaine

A US firm confirmed that AI-hallucinated vulnerability entries for SQLite are passing initial triage and landing in real security reporting pipelines. It's a new attack surface no one designed for.

In plain terms: AI tools are inventing security vulnerabilities that don't exist in real code - and some of those fabricated entries are ending up in the databases security teams use to decide what to patch.

The fact

A US security firm analyzed AI-generated CVE entries targeting SQLite and confirmed that hallucinated vulnerabilities pass initial triage in some automated pipelines and enter real security reporting systems, according to ITmedia AI+. The entries describe bugs absent from SQLite's actual codebase. CVE stands for Common Vulnerabilities and Exposures - the global index that security tools, scanners, and patch managers depend on.

Our take

This is the supply-chain version of AI hallucination, and the consequences scale differently from a chatbot making something up. The NVD (National Vulnerability Database) is already backlogged - it has struggled to process legitimate submissions for years. Fake entries don't just waste analyst time: they generate false positives for automated scanners, potentially crowding out real vulnerabilities in prioritization queues. Any security workflow that ingests CVE feeds without human validation now carries structural risk. The fix isn't straightforward - CVE reporting is semi-automated by design, and retrofitting an AI-origin flag requires coordination between MITRE, NIST, and hundreds of downstream vendors.

What to watch

Whether MITRE updates submission policies to require provenance disclosure, and whether major security platforms start flagging AI-assisted CVE entries in their feeds.

Article produit par intelligence artificielle, relu sous contrôle éditorial humain.

Notre rédaction
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
Cet article vous a-t-il été utile ?

3 personnes ont aimé cet article

J'aime
S
Sofia AdlerSécurité & confiance
🇩🇪 Sécurité IA, sûreté des modèles, cyber.
Partager :
Commentaires (3)

Connectez-vous pour rejoindre la discussion.

TravelTom 05 Aug 2026 · 13:13

Isn’t the real issue that vulnerability databases need better verification systems before AI gets involved, rather than blaming the AI itself?

FoodieChicago 05 Aug 2026 · 12:48

This is a serious problem. AI-generated vulnerabilities could dilute real threats over time, making it harder to prioritize actual risks effectively.

Alex_LDN 05 Aug 2026 · 12:46

That's worrying. If AI is creating fake vulnerabilities, it could waste a lot of teams' time chasing dead ends. How will we ever trust automated threat detection if the sources themselves are unreliable?

Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Rubriques
Explorer
Informations