10/06/2026 | Press release | Distributed by Public on 10/06/2026 07:01
BM (NYSE: IBM) and Red Hat today announced that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and remediation.
"AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together."
Gunnar Hellekson
Vice president and general manager, Lightwell, Red Hat
The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications.
Many security tools can identify potential problems, but detection alone does not remove the risk. Organizations also need fixes that work with the software versions already running in production and can be introduced without disrupting business operations.
Through Lightwell, Red Hat and IBM have uncovered, remediated, and backported fixes for more than 400 previously unknown bugs in widely deployed, production-grade software. The work shows that even mature codebases require continued attention as threats evolve. Red Hat and IBM are focusing engineering resources on this foundational software to help reduce risk across enterprise systems.
Lightwell builds on IBM and Red Hat's commitment to secure open source software for the AI era. The initiative combines several key capabilities:
This powerful engine rapidly develops version-specific fixes for open source application dependencies in production systems. The remediations are delivered through secured repositories that connect with customers' existing IT processes. This allows organizations to address difficult or previously unknown vulnerabilities without replacing their current security scanners, software repositories, development pipelines or testing processes.
Through Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities. With the general availability of Lightwell Clearinghouse, customers can submit specific open source vulnerabilities to IBM and Red Hat for priority review, remediation and fixes that can be applied to older software versions still in use.
In alignment with Red Hat's open source leadership, applicable fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols. This helps the broader open source ecosystem benefit from Lightwell's scale while maintaining embargo protections for Clearinghouse participants.
Supporting Quotes
Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat
"AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started."
In short
Lightwell attains vulnerability milestone with over 400 novel vulnerabilities fixed.
Mentioned in this article
IBM, Red Hat, Lightwell
For more information
Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere-from the datacenter to the edge. As the world's leading provider of enterprise open source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow's IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure and manage their IT environments, supported by consulting services and award-winning training and certification offerings.
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity and service. Visit https://www.ibm.com for more information.
Except for the historical information and discussions contained herein, statements contained in this press release may constitute forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. Forward-looking statements are based on the company's current assumptions regarding future business and financial performance. These statements involve a number of risks, uncertainties and other factors that could cause actual results to differ materially. Any forward-looking statement in this press release speaks only as of the date on which it is made. Except as required by law, the company assumes no obligation to update or revise any forward-looking statements.
###
Red Hat, Red Hat Enterprise Linux, the Red Hat logo, JBoss, Ansible, Ceph, Gluster and OpenShift are trademarks or registered trademarks of Red Hat, LLC. or its subsidiaries in the U.S. and other countries. Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries. The OPENSTACK logo and word mark are trademarks or registered trademarks of OpenInfra Foundation, used under license.