A new research paper proposes using AI to decide which security vulnerabilities actually need fixing first.
Posted to arXiv on October 7, the paper describes Polar, a framework that uses large language models to pull together vendor advisories, vulnerability databases, and threat-intelligence reports into a single assessment per threat. Polar first sorts out overlapping incidents so the same flaw doesn't get double-counted under different names across sources. It then estimates how likely a vulnerability is to be exploited soon by combining inferred severity scores with a timeline of real-world exploitation signals. For each ranked threat, it also pulls in authoritative remediation guidance and sorts the available fixes by urgency and by what a given security team can realistically act on. The researchers tested it against multiple baseline methods on real vulnerability evidence, including zero-day cases, and reported better threat ranking and better retrieval of relevant mitigations.
That matters because the bottleneck in security operations usually isn't knowing a vulnerability exists, it's deciding which of a hundred flagged issues to fix this week. Standard severity scores like CVSS describe how bad a bug could be in theory, not whether anyone is actively exploiting it right now. A system that ties prioritization to evidence an analyst can actually inspect, instead of a black-box score, is the more interesting claim here than the AI label attached to it.
For now this is a research benchmark, not a deployed tool. It still has to prove it holds up on the messy, contradictory feeds real security teams work with outside a curated test set - and that's where most "AI reads your threat intel for you" pitches have stumbled before.