LLMs are often marketed as transformative tools capable of automating complex tasks, such as identifying and fixing security vulnerabilities. However, in practice, LLMs face significant technological and operational limitations. This talk examines why LLMs, despite their impressive language understanding and contextual reasoning capabilities, are often ill-suited for critical aspects of vulnerability management, including open source dependencies, contextual prioritization, supply-chain attacks, and operational remediation.