IBM & Red Hat launch Lightwell remediation service
Tue, 6th Oct 2026 (Yesterday)
IBM and Red Hat said Lightwell has remediated more than 400 previously unknown vulnerabilities in widely used Java libraries and that Lightwell Clearinghouse is now generally available to enterprise customers.
The announcement expands Lightwell from identifying software weaknesses to fixing open source components already running in production systems.
Both companies are framing the effort around a problem facing large organisations that rely on ageing but still widely used software libraries. Many security tools can flag potential issues, but businesses often still need engineering work to create patches for older software versions without disrupting live applications.
IBM and Red Hat said the 400-plus vulnerabilities were previously unknown and were found in common Java libraries used across enterprise environments. The work included backported fixes, with patches adapted for software versions still in use rather than only the latest releases.
That is significant for companies with large application estates, where replacing or upgrading core dependencies can be slow, expensive or operationally risky. In such environments, a vulnerability may be known in principle, but a practical fix that works in a production system can remain out of reach for months.
Production focus
Lightwell is designed to address that gap by focusing on remediation rather than detection alone. The service develops version-specific fixes for open source application dependencies and delivers them through secured repositories that can connect with existing IT processes.
This approach is intended to let customers use remediated software without changing their existing scanners, repositories, development pipelines or testing procedures. Through the Lightwell Network, IT teams can access patches and integrate them into established software management workflows.
The broader commercial step is the general availability of Lightwell Clearinghouse. The service allows enterprise customers to submit specific open source software dependencies for priority review and remediation, including fixes that can be applied to older software versions still in service.
IBM and Red Hat said applicable fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols. That model allows the original software projects to benefit from the remediation work while preserving embargo protections for Clearinghouse participants.
AI pressure
IBM and Red Hat linked the move to a shift in the threat environment driven by increasingly autonomous AI agents. They argue that such tools can combine several individually lower-risk weaknesses into a more serious chain of attack, increasing pressure on organisations to fix known and unknown flaws in software already deployed across critical systems.
The concern reflects a wider debate in cyber security over whether AI will change the economics of offensive operations. Security teams have long struggled to keep pace with patching and dependency management, particularly in open source software that underpins business applications but may not be regularly updated once deployed.
Against that backdrop, Lightwell combines engineering teams from IBM and Red Hat with AI-assisted workflows, Red Hat's open source relationships and software supply chain infrastructure. The setup is intended to produce tested remediations for production software rather than simply report defects.
Gunnar Hellekson, Vice President and General Manager, Lightwell, Red Hat, said the speed and nature of attacks had changed. "AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralising 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started," Hellekson said.
The initiative also sits within a broader partnership between IBM and Red Hat around open source software and AI. The companies have increased their focus on securing software supply chains and maintaining older open source components that continue to support critical enterprise applications.
For customers, the practical test will be whether Lightwell can provide patches quickly enough, and in sufficient volume, to reduce the growing backlog of vulnerable dependencies in production estates.