Fixes across widely-used Java libraries help address security gaps that AI agents could combine into attacks
– Lightwell Clearinghouse is now generally available, giving businesses a direct path to request priority review and remediations for open source software
RALEIGH, N.C. and ARMONK, N.Y. – October 6, 2026 – IBM (NYSE: IBM) and Red Hat today announced that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and remediation.
The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications.
Moving from finding vulnerabilities to remediating them
Many security tools can identify potential problems, but detection alone does not remove the risk. Organizations also need fixes that work with the software versions already running in production and can be introduced without disrupting business operations.
Through Lightwell, Red Hat and IBM have uncovered, remediated, and backported fixes for more than 400 previously unknown bugs in widely deployed, production-grade software. The work shows that even mature codebases require continued attention as threats evolve. Red Hat and IBM are focusing engineering resources on this foundational software to help reduce risk across enterprise systems.
How Lightwell works
Lightwell builds on IBM and Red Hat’s commitment to secure open source software for the AI era. The initiative combines several key capabilities:
- Open source engineering expertise from Red Hat and IBM;
- Red Hat’s deep open source community relationships;
- Advanced AI-assisted engineering workflows; and
- Red Hat’s secure software supply chain capabilities and build infrastructure.
This powerful engine rapidly develops version-specific fixes for open source application dependencies in production systems. The remediations are delivered through secured repositories that connect with customers’ existing IT processes. This allows organizations to address difficult or previously unknown vulnerabilities without replacing their current security scanners, software repositories, development pipelines or testing processes.
Through Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities. With the general availability of Lightwell Clearinghouse, customers can submit specific open source vulnerabilities to IBM and Red Hat for priority review, remediation and fixes that can be applied to older software versions still in use.
In alignment with Red Hat’s open source leadership, applicable fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols. This helps the broader open source ecosystem benefit from Lightwell’s scale while maintaining embargo protections for Clearinghouse participants.
Supporting Quotes
Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat
“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralizing 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started.”












































