IBM and Red Hat has alerted users that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.

The companies also announced the general availability of Lightwell Clearinghouse which allows enterprise customers to submit specific open source software dependencies for priority review and remediation.

“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed,” says Gunnar Hellekson, vice-president and GM of Lightwell, Redhat. “They do not care if a codebase is 10 years old or otherwise considered stable because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime.

“Finding and neutralising 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started,” he says.

As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications.

 

Moving from finding vulnerabilities to remediating them

Many security tools can identify potential problems, but detection alone does not remove the risk. Organisations also need fixes that work with the software versions already running in production and can be introduced without disrupting business operations.

Through Lightwell, Red Hat and IBM have uncovered, remediated, and backported fixes for more than 400 previously unknown bugs in widely deployed, production-grade software.

The work shows that even mature codebases require continued attention as threats evolve.

Red Hat and IBM are focusing engineering resources on this foundational software to help reduce risk across enterprise systems.